MakeBug Micropoor@163.com
'Conn. asp
<%
On Error Resume Next
Servermappath = server. mappath ("/serverinfo. asa ")
& Apos;
DBstr = "" & txt. ReadLine & "'database address name
& Apos;
%>
Read serverinfo. asa
'Serverinfo. asa
/Chinammc_data/chinammc_shop.mdb
Usage:
Http://www.bkjia.com/serverinfo. asa
'\ Fd_upload \ upfile. asp
<Title> File Upload </title>
<! -- # Include file = "class. asp" -->
<%
& Apos;
If upload. form ("EditName") <> "x_file" then
If fileExt <> "swf" and fileExt <> "jpg" and fileExt <> "gif" and fileExt <> "bmp" and fileExt <> "jpeg" and fileExt <>" tif "then %>
<Span style = "" font-family:; font-size: 9pt ""> the upload is aborted! Only files in image format can be uploaded! [<A href = # onclick = history. go (-1)> re-upload </a>] </span>
& Apos;
%>
Classic Upload Vulnerability.
Default address:
Http://www.bkjia.com/fd_upload/upload. asp
Default eWebEditor logon address:
Http://www.bkjia.com/_ eWebEditor/760706bjsdyt_2007-0827.asp
Default database address:
Http://www.bkjia.com/_ eWebEditor/yasda612376asdga656qtfyfsw656q/35275twfd3562108wsayqtwreq. mdb
Fixed: fixing problems one by one is not an esoteric problem.