NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
13571  CVE-2010-2084  Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits from HtmlContainerControl, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to an attribute.    4.3  Medium  2017-01-18  2010-05-28  View
13572  CVE-2010-2085  The default configuration of ASP.NET in Microsoft .NET before 1.1 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the __VIEWSTATE parameter.    4.3  Medium  2017-01-18  2010-05-28  View
13573  CVE-2010-2086  Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.    Medium  2017-01-18  2010-05-28  View
13574  CVE-2010-2087  Oracle Mojarra 1.2_14 and 2.0.2, as used in IBM WebSphere Application Server, Caucho Resin, and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.    4.3  Medium  2017-01-18  2013-01-28  View
13575  CVE-2010-2088  ASP.NET in Microsoft .NET 3.5 does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks against the form control via the __VIEWSTATE parameter.    4.3  Medium  2017-01-18  2010-05-28  View

Page 2715 of 17672, showing 5 records out of 88360 total, starting on record 13571, ending on 13575

Actions