|
Microsoft .NET Framework contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the component provides detailed error codes during decryption attempts, which will disclose View State form data to a remote attacker via a padding oracle attack. This may also potentially allow for the forging of cookies or reading of application files.
|