Description
Acunetix detected that MAC validation is not enabled for the ViewState. An attacked can tamper with the ViewState and potentially exploit the application.
Remediation
ASP.NET uses a hash code-based integrity solution called "ViewStateMac" to protect ViewState parameters against tampering attacks. You can implement this solution on a page or application level.
References
Related Vulnerabilities
Joomla! Core 1.7.x Information Disclosure (1.7.0 - 1.7.4)
Tiki Wiki CMS: Arbitrary File Download
WordPress Plugin Advanced Contact form 7 DB Information Disclosure (1.1.0)
WordPress Plugin Wp-ImageZoom 'file' Parameter Information Disclosure (1.0.3)
WordPress Plugin Plugin:Newsletter 'data' Parameter Information Disclosure (1.5)