PT-2005-2641 · Microsoft · Asp.Net

Michal Zalewski

·

Published

2005-05-18

·

Updated

2017-07-11

·

CVE-2005-1664

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft ASP.NET version 1.x
Description The issue concerns the VIEWSTATE functionality, which allows remote attackers to conduct replay attacks. This can be used to apply a ViewState generated from one view to a different view, reuse ViewState information after the application's state has changed, or use the ViewState to conduct attacks or expose content to third parties.
Recommendations For Microsoft ASP.NET version 1.x, consider implementing proper validation and restrictions on ViewState usage to prevent replay attacks, such as using page-specific ViewState or implementing a mechanism to track and validate ViewState generation and usage.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1664

Affected Products

Asp.Net