<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>80sec &#187; Vulnerability</title>
	<atom:link href="http://www.80sec.com/tag/vulnerability/feed" rel="self" type="application/rss+xml" />
	<link>http://www.80sec.com</link>
	<description>Know it then hack it!</description>
	<lastBuildDate>Thu, 19 Aug 2010 08:43:01 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Microsoft Internet Infomation Server 6.0 ISAPI Filename Analytic Vulnerability</title>
		<link>http://www.80sec.com/microsoft-internet-infomation-server-6-isapi-filename-analytic-vulnerabilitie.html</link>
		<comments>http://www.80sec.com/microsoft-internet-infomation-server-6-isapi-filename-analytic-vulnerabilitie.html#comments</comments>
		<pubDate>Fri, 24 Apr 2009 06:39:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[漏洞发布]]></category>
		<category><![CDATA[Filename]]></category>
		<category><![CDATA[IIS6]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://www.80sec.com/?p=57</guid>
		<description><![CDATA[Microsoft Internet Infomation Server 6.0 ISAPI Filename Analytic Vulnerability
function Copyright()
{
	var Author=&#8221;80sec&#8221;;
	var Email=&#8221;kEvin#80sec.com&#8221;.replace(&#8220;#&#8221;,&#8221;@&#8221;)
	var Site=&#8221;http://www.80sec.com&#8221;;
	var Date=new Date(2009,4,24).toLocaleString();
	var Reference=&#8221;http://www.80sec.com/Microsoft-Internet-Infomation-Server-6-ISAPI-filename-analytic-Vulnerabilitie.html&#8221;;
	return Reference;
}
/*
	漏洞描述:
	
		IIS6 (Internet Infomation Server 6.0) 是微软出品的一款WEB服务器系统, 广泛用于各种个人/商业信息发布/网站架设领域。80sec在测试中发现, IIS设计上在处理畸形文件名的时候存在一个严重的安全漏洞, 可能绕过web程序的逻辑检查从而能导致服务器以IIS进程权限执行任意恶意用户定义的脚本, 黑客可以通过制造畸形的服务器文件来触发该	漏洞, 并从而控制服务器.
	漏洞厂商: 
		Microsoft [ http:\/\/www.microsoft.com ]
	漏洞测试:
		Undefined
	解决方案:
		等待微软更新官方补丁.
*/
]]></description>
			<content:encoded><![CDATA[<p>Microsoft Internet Infomation Server 6.0 ISAPI Filename Analytic Vulnerability</p>
<p>function Copyright()<br />
{</p>
<p>	var Author=&#8221;80sec&#8221;;<br />
	var Email=&#8221;kEvin#80sec.com&#8221;.replace(&#8220;#&#8221;,&#8221;@&#8221;)<br />
	var Site=&#8221;http://www.80sec.com&#8221;;<br />
	var Date=new Date(2009,4,24).toLocaleString();<br />
	var Reference=&#8221;http://www.80sec.com/Microsoft-Internet-Infomation-Server-6-ISAPI-filename-analytic-Vulnerabilitie.html&#8221;;<br />
	return Reference;</p>
<p>}</p>
<p>/*</p>
<p>	漏洞描述:<br />
	<span id="more-57"></span><br />
		IIS6 (Internet Infomation Server 6.0) 是微软出品的一款WEB服务器系统, 广泛用于各种个人/商业信息发布/网站架设领域。80sec在测试中发现, IIS设计上在处理畸形文件名的时候存在一个严重的安全漏洞, 可能绕过web程序的逻辑检查从而能导致服务器以IIS进程权限执行任意恶意用户定义的脚本, 黑客可以通过制造畸形的服务器文件来触发该	漏洞, 并从而控制服务器.</p>
<p>	漏洞厂商: </p>
<p>		Microsoft [ http:\/\/www.microsoft.com ]</p>
<p>	漏洞测试:</p>
<p>		Undefined</p>
<p>	解决方案:</p>
<p>		等待微软更新官方补丁.</p>
<p>*/</p>
]]></content:encoded>
			<wfw:commentRss>http://www.80sec.com/microsoft-internet-infomation-server-6-isapi-filename-analytic-vulnerabilitie.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
