Unrated severityNVD Advisory· Published Aug 27, 2008· Updated Apr 23, 2026
CVE-2008-3843
CVE-2008-3843
Description
Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework with the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a query string containing a "<~/" (less-than tilde slash) sequence followed by a crafted STYLE element.
Affected products
3cpe:2.3:a:microsoft:.net_framework:1.0:sp3:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:microsoft:.net_framework:1.0:sp3:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:1.1:sp1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:.net_framework:2.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- securityreason.com/securityalert/4193nvd
- www.procheckup.com/PDFs/bypassing-dot-NET-ValidateRequest.pdfnvd
- www.procheckup.com/Vulnerability_PR08-20.phpnvd
- www.securityfocus.com/archive/1/495667/100/0/threadednvd
- www.securityfocus.com/archive/1/496071/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/44743nvd
News mentions
0No linked articles in our index yet.