Description
Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework with the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a query string containing a "<~/" (less-than tilde slash) sequence followed by a crafted STYLE element.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T09:53:00.395Z
Reserved: 2008-08-27T00:00:00.000Z
Link: CVE-2008-3843
No data.
Status : Modified
Published: 2008-08-27T20:41:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2008-3843
No data.
OpenCVE Enrichment
No data.
Weaknesses