Microsoft IIS6 解析目录“xxx.asp”漏洞

影响版本:
IIS6.0 or lower
漏洞描述:
Application:Microsoft Internet Information Services (IIS)
Note:Tested on IIS 6.0 Work successfully
##########################################################

hackers build a directory called aaa.asp then aaa.asp directory put a picture 
inside the Trojans , hackers access aaa.asp/xxx.jpg will be able to access trojan !

Original document:
http://blog.pouya.info/userfiles/vul/IIS0day.pdf
<*参考

http://blog.pouya.info/userfiles/vul/IIS0day.pdf
http://securitylab.ir/bt/IIS0day.zip

*>

发表评论?

0 条评论。

发表评论