Test Methods ( Detailed Overview )

Here is a list of every test performed by Web Scan Service.

Microsoft ASP.NET or ASP Unicode Conversion Cross-Site Scripting

Remediation Task

Filter out hazardous characters from user input

WASC Classification

Client-side Attacks: Cross-site Scripting

Affected Products

ASP.NET

Technical Description

Multiple Cross-Site Scripting vulnerabilities exist when Unicode characters ranging from U+ff00-U+ff60 are converted to ASCII due to insufficient validation, which could let a remote malicious user execute arbitrary HTML or script code.

Fix Recommendation

Filter out ASCII characters from user input.