CERT-In Vulnerability Note
CIVN-2014-0228
cross-site scripting (XSS) vulnerability exists in ASP.NET MVC
Original Issue Date:October 15, 2014
Severity Rating: MEDIUM
Systems Affected
- ASP.NET MVC 2.0
- ASP.NET MVC 3.0
- ASP.NET MVC 4.0
- ASP.NET MVC 5.0
- ASP.NET MVC 5.1
Overview
A vulnerability has been reported in Microsoft ASP.NET MVC which could allow a remote attacker to conduct cross-site scripting (XSS) attacks.
Description
This vulnerability exists in System.Web.Mvc.dll component of ASP.NET due to improper encoding of user-supplied input by the affected software. A remote attacker could exploit this vulnerability by convincing a user to open a crafted web page to inject a client-side script into the user¿s instance of Internet Explorer.
Successful exploitation could allow the attacker to spoof content, disclose information, or conduct other attacks.
Workaround
- Set Internet and Local intranet security zone settings to "High" to block ActiveX Controls and Active Scripting in these zones
- Add trusted sites to the Internet Explorer Trusted sites zone
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS14-059
Vendor Information
Microsoft
https://technet.microsoft.com/library/security/ms14-059
References
Microsoft
https://technet.microsoft.com/library/security/ms14-059
http://support.microsoft.com/kb/2883031
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=35975
SecurityFocus
http://www.securityfocus.com/bid/70352
CVE Name
CVE-2014-4075
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|