IT

Tracker / CVE-2017-0249

CVE-2017-0249

High 7.3

An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.

Affected products and versions

microsoft asp.net_model_view_controller
microsoft microsoft.aspnetcore.mvc.abstractions
microsoft microsoft.aspnetcore.mvc.apiexplorer
microsoft microsoft.aspnetcore.mvc.cors
microsoft microsoft.aspnetcore.mvc.dataannotations
microsoft microsoft.aspnetcore.mvc.formatters.json
microsoft microsoft.aspnetcore.mvc.formatters.xml
microsoft microsoft.aspnetcore.mvc.localization
microsoft microsoft.aspnetcore.mvc.razor
microsoft microsoft.aspnetcore.mvc.razor.host
microsoft microsoft.aspnetcore.mvc.taghelpers
microsoft microsoft.aspnetcore.mvc.viewfeatures
microsoft microsoft.aspnetcore.mvc.webapicompatshim
microsoft system.net.http
microsoft system.net.http.winhttphandler
microsoft system.net.security
microsoft system.net.websockets.client
microsoft system.text.encodings.web

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References