CVE-2005-0452 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 23.4% (pctl 98)
Patch early
A public exploit exists.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 23.37% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-02-16 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | asp.net |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft ASP.NET 1.0/1.1 - Unicode Character Conversion Multiple Cross-Site Scripting Vulnerabilities | 2005-02-16 |
References
- http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml
- http://marc.info/?l=bugtraq&m=110867912714913&w=2
- http://secunia.com/advisories/14214
- http://www.securityfocus.com/bid/12574
- http://it-project.ru/andir/docs/aspxvuln/aspxvuln.en.xml
- http://marc.info/?l=bugtraq&m=110867912714913&w=2
- http://secunia.com/advisories/14214
- http://www.securityfocus.com/bid/12574
→ the Explorer · watch your stack · NVD