---------------------------------------------------------------------- Want a new job? http://secunia.com/secunia_security_specialist/ http://secunia.com/hardcore_disassembler_and_reverse_engineer/ International Partner Manager - Project Sales in the IT-Security Industry: http://corporate.secunia.com/about_secunia/64/ ---------------------------------------------------------------------- TITLE: Mono ASP.net Cross-Site Scripting SECUNIA ADVISORY ID: SA31338 VERIFY ADVISORY: http://secunia.com/advisories/31338/ CRITICAL: Not critical IMPACT: Cross Site Scripting WHERE: >From remote SOFTWARE: Mono 1.x http://secunia.com/product/4673/ DESCRIPTION: Dean Brettle has reported some security issues in Mono, which can be exploited by malicious people to conduct cross-site scripting attacks. The security issues are caused due to Mono's ASP.net implementation not properly sanitising certain attributes (e.g. "HtmlSelect.Value", "HtmlSelect.Text", and the "action" attribute of the "