Microsoft_ASP_NET_ViewState_Denial_of_Service_attack

Strike ID:
G05-4a901
CVSS:
5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
False Positive:
f
Variants:
1
Year:
2005

Description

It has been reported that Microsoft's ASP.NET is affected by an input sanitization vulnerability. The problem is triggered when the product parses crafted web session state information. Successfully exploiting the vulnerability can cause the target to consume large amounts of computing resources, resulting in degraded performance or a denial of service. Note, that after the attack is halted the system will eventually return to normal operating status.

CVE

References