← All CVEs

CVE-2010-3332

medium · 6.4

Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."

6.4
CVSS
68.2%
EPSS (exploit prob.)
99th
EPSS percentile
2010-09-22
Published

AV:N/AC:L/Au:N/C:P/I:P/A:N

Weaknesses

CWE-209

Affected products

VendorProductAffected versions
microsoft.net_framework1.1
microsoft.net_framework2.0
microsoft.net_framework2.0
microsoft.net_framework3.5
microsoft.net_framework3.5
microsoft.net_framework3.5.1
microsoft.net_framework4.0
microsoftinternet_information_servicesall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-3332