Network Security Internet Technology Development Database Servers Mobile Phone Android Software Apple Software Computer Software News IT Information

In addition to Weibo, there is also WeChat

Please pay attention

WeChat public account

Shulou

Siteserver cms 3.4.5+iis6.0 loophole and its repair

2025-04-05 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > Network Security >

Share

Shulou(Shulou.com)06/01 Report--

But after my local test, I found that only xxx.asp folders can exploit this vulnerability!

This vulnerability is very similar to the original loophole!

Meet two conditions for open registration of the system iis6

Register account-> document attachment Management-> upload Files We can create a new layer directory before of course * .asp directory has been filtered in 3.4.5

Let's set up a catalog! Arbitrary name

At this time, we uploaded files and found that upload jpg gif format is not good, but txt can upload, command XX.ASP;.TXT can not upload

You have to be flexible and upload it on XX.CER;.txt.

The repair method is nothing more than fixing the parsing and folder read and write permissions http://www.2cto.com/Article/201203/122038.html of iis6.0.

Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.

Views: 0

*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.

Share To

Network Security

Wechat

© 2024 shulou.com SLNews company. All rights reserved.

12
Report