Intrusion Prevention

MS.ASP.NET.ValidateRequest.XSS

Description

This indicates an attack attempt to exploit a Cross Site Scripting vulnerability in Microsoft ASP.NET Frame work.
The vulnerability is due to an error when the vulnerable software attempts to handle a maliciously crafted webpage. An attacker can exploit this by tricking a user into visiting a malicious webpage and execute arbitrary script code within the context of the application.

Affected Products

Windows 2008
Windows 2003
Windows 2000
Windows Vista
Windows XP
ASP.NET Framework 2.0 or prior version

Impact

System Compromise: Remote attackers can execute arbitrary script code within the context of the target user's browser

Recommended Actions

Apply the most recent upgrade or patch from the vendor

CVE References

CVE-2008-3843 CVE-2008-3842