Due to the inherent functionality of HTTP-GET and HTTP-POST messaging protocols, it is possible under certain conditions for a malicious Web page to invoke an XML Web service running behind a firewall using parameters defined by the malicious Web page. This is similar to other issues involving malicious redirects based on the HTTP-GET. This can occur if the XML Web service supports communication using the HTTP-GET or HTTP-POST messaging protocols, which are enabled by default for XML Web services created using ASP.NET.
|