Check Point Reference: | CPAI-2014-1880 |
Date Published: | 14 Oct 2014 |
Severity: | High |
Last Updated: | Tuesday 14 October, 2014 |
Source: | Microsoft Security Bulletin MS14-059 |
Industry Reference: | CVE-2014-4075 |
Protection Provided by: | |
Who is Vulnerable? | ASP.NET MVC 2.0 ASP.NET MVC 3.0 ASP.NET MVC 4.0 ASP.NET MVC 5.0 ASP.NET MVC 5.1 |
Vulnerability Description | A cross-site scripting vulnerability has been reported in ASP.NET MVC. The vulnerability is due the way ASP.NET MVC improperly handles encoded input. A remote attacker can exploit this vulnerability by enticing an affected user to open a malicious web-page. |