Web involves programs:
Carello Web on NT running IIS
Describe:
Carello Web enables ASP source code exposure
With:
Carello Web is a software that supports online shopping.
Carello Web There is a security problem that allows a remote attacker to create a file on the system, and if the file already exists, it copies a copy, and the file extension
After a little change. For example: 123.asp will be changed to 123.ASP1 because of the extension change, the file will be read as text by the attacker. An attacker can obtain an ASP source
Get the system password.
Use examples:
Http://charon/scripts/carello/add.exe?c:\inetpub\iissamples\default\samples.asp
A SAMPLES.ASP1 is created and can be read. An attacker would need to know the full path of the file and be able to do so if NTFS allowed anonymous Internet account writes
Work.
Solution:
Download the new version.
Related sites:
http://www.cerberus-infosec.co.uk/
From:http://www.cnns.net/article/db/353.htm