First published: Wed Feb 16 2005(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft ASP.NET | =1.0-sp1 | |
Microsoft ASP.NET | =1.0-sp2 | |
Microsoft ASP.NET | =1.0 | |
Microsoft ASP.NET | =1.1 | |
Microsoft ASP.NET | =1.1-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.