PT-2015-2682 · Microsoft · .Net Framework+1

Publicado

2015-11-10

·

Atualizado

2018-10-12

·

CVE-2015-6099

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft .NET Framework versions 4 through 4.6
Description The issue is related to a cross-site scripting (XSS) vulnerability in ASP.NET, which allows remote attackers to inject arbitrary web script or HTML via a crafted value. This vulnerability exists due to inadequate protection of the web page structure. An attacker could exploit this vulnerability to inject client-side script into a user's browser, potentially modifying or spoofing content, conducting phishing activities, disclosing information, or performing actions on the vulnerable website that the target user has permission to perform. User interaction is required to exploit this vulnerability.
Recommendations For Microsoft .NET Framework versions 4 through 4.6, update to a version that includes the fix for this issue to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-12047
CVE-2015-6099

Produtos afetados

.Net Framework
Asp.Net