Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
PR08-20: Bypassing ASP .NET "ValidateRequest" for Script Injection Attacks Aug 21 2008 08:08PM
ProCheckUp Research (research procheckup com)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

The Microsoft .NET framework comes with a request validation feature,
configurable by the ValidateRequest setting. ValidateRequest has been a
feature of ASP.NET since version 1.1. This feature consists of a series
of filters, designed to prevent classic...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus