Microsoft IIS ASP Remote Code Execution Vulnerability

Microsoft IIS ASP Remote Code Execution Vulnerability

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Microsoft IIS ASP Remote Code Execution Vulnerability imhotep 07-18-2006
Posted by imhotep on July 18, 2006, 10:03 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
"Microsoft Internet Information Server (IIS) is prone to a remote
code-execution vulnerability because it fails to properly bounds-check
user-supplied input before copying it to an insufficiently sized memory
buffer.

To exploit this issue, attackers must be able to place and execute malicious
ASP pages on computers running the affected ASP server software. This may
be an issue in shared-hosting environments.

This issue allows remote attackers to execute arbitrary machine code in the
context of the affected webserver software."

http://www.securityfocus.com/bid/18858/discuss

-- Imhotep

Similar ThreadsPosted
MS07-040 - remote code execution in .NET Framework? July 10, 2007, 7:20 pm
SSRT4788 rev. 0 HP-UX Apache Remote arbitary code execution August 9, 2004, 12:30 pm
SSRT4788 rev. 1 HP-UX Apache Remote arbitrary code execution August 13, 2004, 11:46 am
SSRT4777 rev. 0 HP-UX Apache, PHP remote code execution, Denial of Service August 5, 2004, 2:06 pm
SSRT4777 rev. 1 HP-UX Apache, PHP remote code execution, Denial of Service August 13, 2004, 11:45 am
SSRT051040 rev.0 - HP-UX Mozilla Remote Unauthorized Execution of Privileged Code October 4, 2005, 9:59 pm
HPSBUX02196 SSRT071318 rev.2 - HP-UX Java (JRE and JDK) Remote Execution of Arbitrary Code March 12, 2007, 10:18 am
HPSBUX02108 SSRT061133 rev.6 - HP-UX running Sendmail, Remote Execution of Arbitrary Code April 13, 2006, 8:10 am
HPSBUX02108 SSRT061133 rev.1 - HP-UX running Sendmail, Remote Execution of Arbitrary Code March 30, 2006, 2:14 pm
HPSBUX02108 SSRT061133 rev.2 - HP-UX running Sendmail, Remote Execution of Arbitrary Code March 31, 2006, 10:10 am

The site map in XML format XML site map

Contact Us | Privacy Policy