A few hours ago Microsoft posted a security advisory about a security vulnerability in ASP.NET. This vulnerability exists in all versions of ASP.NET.
This vulnerability was announced and the tools to exploit the vulnerability were released late Friday at a “Security Conference”.
For DotNetNuke users Cathal Connolly, our Security Specialist has posted a blog on how DotNetNuke users can mitigate against this potential attack.
The good news is – there are steps to mitigate the attacks.
For more information:
Forms Authentication Vulnerability in ASP.NET – Shaun Walker – CoFounder and CTO, DotNetNuke Corporation
ASP.NET Security Vulnerability workaround for DotNetNuke sites – Cathal Connoly, Security Specialist, DotNetNuke Corporation
Important: ASP.NET Security Vulnerability - blog by Scott Guthrie, Corporate Vice-President, Microsoft Corporation
Microsoft Security Bulletin
ced59405-c3ec-44d1-a324-7c426f8501fa|0|.0