CVE-2010-2084
medium · 4.3Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits from HtmlContainerControl, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to an attribute.
4.3
CVSS
12.5%
EPSS (exploit prob.)
96th
EPSS percentile
2010-05-27
Published
AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | asp.net | 2.0 |
Check a specific version with /api/v1/cve/match.
References
- http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2010/03/30/configuration-is-half-the-battle-asp-net-and-cross-site-scripting.aspx
- http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2010/03/30/configuration-is-half-the-battle-asp-net-and-cross-site-scripting.aspx
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2010-2084