exploit-db-mirror/platforms/linux/remote/32303.txt
Offensive Security 21ed45f856 Updated 03_18_2014
2014-03-18 04:28:55 +00:00

9 lines
No EOL
692 B
Text
Executable file

source: http://www.securityfocus.com/bid/30867/info
Mono is prone to a vulnerability that allows attackers to inject arbitrary HTTP headers because it fails to sanitize input.
By inserting arbitrary headers into an HTTP response, attackers may be able to launch cross-site request-forgery, cross-site scripting, HTTP-request-smuggling, and other attacks.
This issue affects Mono 2.0 and earlier.
<script runat="server"> void Page_Load(object o, EventArgs e) { // Query parameter text is not checked before saving in user cookie NameValueCollection request = Request.QueryString; // Adding cookies to the response Response.Cookies["userName"].Value = request["text"]; } </script>