Search:     Advanced search
server monitoring

Apache ASP module Apache::ASP source.asp Example File Arbitrary File Creation

Article ID: 10480
Last updated: 27 Jan, 2009
Views: 412
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

Apache ASP module Apache::ASP source.asp Example File Arbitrary File Creation

This script is Copyright (C) 2000-2008 Tenable Network Security, Inc.

FamilyWeb Servers
Plugin ID10480
Bugtraq ID1457
CVE IDCVE-2000-0628

Description:

The file /site/eg/source.asp is present.

This file comes with the Apache::ASP package and allows anyone to write to files in the
same directory.

An attacker may use this flaw to upload his own scripts and execute arbitrary commands
on this host.

Solution : Upgrade to Apache::ASP 1.95
Risk factor : High
This article was:   Helpful | Not Helpful
Prev   Next
Apache HTTP Server Socket Connection Blocking Race Condition DoS     Microsoft IIS 5 .printer ISAPI Filter Enabled