Description
MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.
Affected products
- microsoft / site_server2.0 – 2.0
Exploits & proofs of concept
- exploit-dbMicrosoft Site Server 2.0 with IIS 4.0 - Arbitrary File Uploadby Mnemonix
References
- MAILING_LISThttp://marc.info/?l=bugtraq&m=91763097004101&w=2
Updated 11m ago · 8 sources