Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: FW: [Alert] Website's uploader.exe (from demo) vulnerable

Re: FW: [Alert] Website's uploader.exe (from demo) vulnerable

From: David J. Meltzer <davem_at_ISS.NET>
Date: Fri, 5 Sep 1997 17:30:33 -0400

> >O'reilly's webserver 'website' contains a demopackage that contains
> >the cgi-program uploader.exe.
> >The program uploader.exe doesn't check anything at all.....
>
> This hole did exist prior to the July 1996 revision of uploader.bas,
> when I added a security fix.
> The fix has been available since that time at
> http://software.ora.com/techsupport/software/updates.html
> The revised uploader was also included in WebSite 1.1g

FYI-
  The current WebSite Professional 2.0 Beta is vulnerable to the
uploader.exe problem. Of course being beta code it is expected
to have bugs but just want to be sure you are aware so it gets
fixed before 2.0 hits a release.

-Dave

--------------------------------+---------------------
       David J. Meltzer | Email: davem_at_iss.net
       Systems Engineer | Web: www.iss.net
Internet Security Systems, Inc. | Fax: (770)395-1972
Received on Sep 05 1997

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]