Vulnerabilities > CVE-2003-0768 - Cross-Site Scripting vulnerability in Microsoft Asp.Net 1.1

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
microsoft

Summary

Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character in the beginning of a tag name.

Vulnerable Configurations

Part Description Count
Application
Microsoft
1