From sentiment Blog
SiteServer CMS website content management system is based on Microsoft. the website content management system developed on the. NET platform, it integrates multiple powerful functions such as content publishing management, multi-site management, scheduled content collection, scheduled generation, multi-server Publishing, search engine optimization, and traffic statistics. It is a unique STL template language, you can use the Dreamweaver visualization plug-in to edit the page display style and generate a static page.
Because the file name is not filtered and automatically renamed during attachment upload, The 1.asp; jpg malformed file is uploaded. Attackers can exploit the IIS6.0 executable code vulnerability to obtain the website shell.
Vulnerability exploitation: first enter usercenter/register. aspx to register the user, and then usercenter/login. aspx to log on to the background. Go to the management center and upload the attachment shell.asp;jpg;shell.asp;.jpg. You can obtain the shell address through browsing.