Collected research
Microsoft ASP.NET Request Validation Bypass Vulnerability
ProCheckUp - Security Vulnerabilities 2007
ProCheckUp advisory PR07-03 (CVE-2006-7192): ASP.NET request validation is bypassed by a bogus closing tag carrying a CSS expression, with comments splitting the keyword as e/**/xpression. Four payloads cover alert, redirect, cookie theft and injecting a full login form from an external .js file. Fixed by MS07-040.
Record
- Document
- ProCheckUp - Security Vulnerabilities 2007
- Researcher
- Richard Brain, Jan Fry and Adrian Pastor
- Published by
- procheckup.com
- Topic
- Server
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Richard Brain, Jan Fry and Adrian Pastor, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .