Microsoft has patched a Cross Site Scripting (XSS) vulnerability in the .NET 2.0 framework last October. We have had some reports of security scans picking this vulnerability up on sites "in the wild" still.
There are additional details available here: http://www.microsoft.com/technet/sec.../ms06-056.mspx
Just as a reminder, if you are running a dedicated server, make sure to stay up to date on the latest security patches and updates for not only the operating system, but also the applications themselves (Microsoft SQL Server, IIS, ASP.NET, Mail Server Software, web browsers, Antivirus definitions, etc.).
You can (and should) subscribe to Microsoft's security alerts via email or RSS. More details here: http://www.microsoft.com/technet/sec...in/notify.mspx