Short Name |
HTTP:EXPLOIT:FP2K-ASP-UPLOAD |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Microsoft FrontPage 2000 ASP File Upload Vulnerability |
Release Date |
2011/11/16 |
Update Number |
2031 |
Supported Platforms |
idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known flaw in FrontPage 2000. Unauthenticated attackers can upload server-side ASP scripts, resulting in arbitrary code execution on the server.
A file upload vulnerability allegedly affects the DATA Access Internet Publishing Service Provider Distributed Versioning and Authoring (DAV) functionality of Microsoft FrontPage 2000. An attacker may leverage this issue to upload arbitrary files to the affected computer. This will allow the execution of server-based script code, and will facilitate a compromise of the affected server. Depending on the purpose on the server, an attacker could also exploit the issue to place malicious or abuse content on the server. It should be noted that the individual reporting this issue may have discovered it while auditing a poorly configured implementation of the affected software; if this were the case this issue may not be a vulnerability. This BID will be updated immediately upon the release of new information.