Upload folders with Write and Execute access are vulnerable (189272)
The information in this article applies to:
- Microsoft Internet Information Server 4.0
This article was previously published under Q189272 We strongly recommend that all users upgrade to Microsoft Internet Information Services (IIS) version 6.0 running on Microsoft Windows Server 2003. IIS 6.0 significantly increases Web infrastructure security. For more information about IIS security-related topics, visit the following Microsoft Web site: SUMMARY
A computer running Internet Information Server (IIS) may be vulnerable to
attack if the following conditions are true:
- IIS is configured to allow users to upload content using RFC 1867
methods.
- The directory that users can upload to has both Write access and
Execute permissions.
Modification Type: | Major | Last Reviewed: | 9/28/2005 |
---|
Keywords: | kbinfo KB189272 kbAudDeveloper |
---|
|