Applications which fail to provide their own filtering on top of the inbuilt .NET request filtering may be vulnerable to XSS attacks. Provided that a web application solely relies on .NET request filtering before echoing input back to the web browser, it is possible to inject scripting code and successfully launch XSS attacks by submitting a specially crafted request.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/51519/xss-.net.txt
Source: https://packetstormsecurity.com/files/51519/xss-.net.txt.html

