Description
Microsoft ASP.Net 1.1 allows remote attackers to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character in the beginning of a tag name.
Affected products
- Microsoft / ASP.NET1.1 – 1.1
References
Updated 43m ago · 2 sources