CVE-2017-0256
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
Published:May 12, 2017
Last Modified:Apr 20, 2025
EPS:May 12, 2017
EPSS Score:0.04349
CVSS Score:5.3
Affected Products
Vendor
Product
Action
Vendor
Microsoft
Product
Asp.net Model View Controller
Microsoft
Asp.net Model View Controller
Vendor
Microsoft
Product
Microsoft.aspnetcore.mvc.abstractions
Microsoft
Microsoft.aspnetcore.mvc.abstractions
Vendor
Microsoft
Product
Microsoft.aspnetcore.mvc.apiexplorer
Microsoft
Microsoft.aspnetcore.mvc.apiexplorer
Vendor
Microsoft
Product
Microsoft.aspnetcore.mvc.cors
Microsoft
Microsoft.aspnetcore.mvc.cors
Vendor
Microsoft
Product
Microsoft.aspnetcore.mvc.dataannotations
Microsoft
Microsoft.aspnetcore.mvc.dataannotations
Vendor
Microsoft
Product
Microsoft.aspnetcore.mvc.formatters.json
Microsoft
Microsoft.aspnetcore.mvc.formatters.json
Vendor
Microsoft
Product
Microsoft.aspnetcore.mvc.formatters.xml
Microsoft
Microsoft.aspnetcore.mvc.formatters.xml
Vendor
Microsoft
Product
Microsoft.aspnetcore.mvc.localization
Microsoft
Microsoft.aspnetcore.mvc.localization
Vendor
Microsoft
Product
Microsoft.aspnetcore.mvc.razor
Microsoft
Microsoft.aspnetcore.mvc.razor
Vendor
Microsoft
Product
Microsoft.aspnetcore.mvc.razor.host
Microsoft
Microsoft.aspnetcore.mvc.razor.host
Vendor
Microsoft
Product
Microsoft.aspnetcore.mvc.taghelpers
Microsoft
Microsoft.aspnetcore.mvc.taghelpers
Vendor
Microsoft
Product
Microsoft.aspnetcore.mvc.viewfeatures
Microsoft
Microsoft.aspnetcore.mvc.viewfeatures
Vendor
Microsoft
Product
Microsoft.aspnetcore.mvc.webapicompatshim
Microsoft
Microsoft.aspnetcore.mvc.webapicompatshim
Vendor
Microsoft
Product
System.net.http
Microsoft
System.net.http
Vendor
Microsoft
Product
System.net.http.winhttphandler
Microsoft
System.net.http.winhttphandler
Vendor
Microsoft
Product
System.net.security
Microsoft
System.net.security
Vendor
Microsoft
Product
System.net.websockets.client
Microsoft
System.net.websockets.client
Vendor
Microsoft
Product
System.text.encodings.web
Microsoft
System.text.encodings.web
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
