CVE-2015-6099: XSS
Cross-site scripting (XSS) vulnerability in ASP.NET in Microsoft .NET Framework 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka ".NET Elevation of Privilege Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6099?
CVE-2015-6099 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2015-6099?
To fix CVE-2015-6099, update to the latest version of the .NET Framework that is not affected by this vulnerability.
Which versions of the .NET Framework are affected by CVE-2015-6099?
CVE-2015-6099 affects .NET Framework versions 4.0, 4.5, 4.5.1, 4.5.2, and 4.6.
What type of vulnerability is CVE-2015-6099?
CVE-2015-6099 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
Can CVE-2015-6099 allow for privilege escalation?
Yes, CVE-2015-6099 can be exploited to elevate privileges through the injection of malicious scripts.