Seleccionar página

X-aspnet-version 4.0.3 Vulnerabilities [ Genuine × 2027 ]

POST /default.aspx HTTP/1.1 X-AspNet-Version: 4.0.30319 Content-Type: application/x-www-form-urlencoded __VIEWSTATE=/wEPDwUKLT... (malicious Base64 blob)

protected void Application_PreSendRequestHeaders(object sender, EventArgs e) x-aspnet-version 4.0.3 vulnerabilities

[X-AspNet-Version: 4.0.30319] Stack Trace: [NullReferenceException: Object reference not set to an instance of an object.] MyApp.DataLayer.GetUser(String id) in C:\Projects\MyApp\DataLayer.cs:line 42 A realistic attack scenario using the exposed header: POST /default

Response.Headers.Remove("X-AspNet-Version"); httpRuntime enableVersionHeader="false" /&gt

<system.web> <httpRuntime enableVersionHeader="false" /> </system.web> :