CVE-2010-3332

Scores

EPSS

0.836high83.6%
0%20%40%60%80%100%

Percentile: 83.6%

CVSS

6.4medium2.0
0246810

CVSS Score: 6.4/10

All CVSS Scores

CVSS 2.0
6.4

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Description

Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka “ASP.NET Padding Oracle Vulnerability.”

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-209

Exploits

Exploit ID: 15213

Source: exploitdb

URL: https://www.exploit-db.com/exploits/15213

Exploit ID: 15265

Source: exploitdb

URL: https://www.exploit-db.com/exploits/15265

Exploit ID: 15292

Source: exploitdb

URL: https://www.exploit-db.com/exploits/15292

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: .net_framework

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:microsoft:.net_framework:1.1:sp1:*:*:*:*:*:*",          "vulnerable": true        },        {          "cpe2...

Source: nvd

End of list