Siteserver cms 3.4.5+iis6.0 loophole and its repair
But after my local test, I found that only xxx.asp folders can exploit this vulnerability!
This vulnerability is very similar to the original loophole!
Meet two conditions for open registration of the system iis6
Register account-> document attachment Management-> upload Files We can create a new layer directory before of course * .asp directory has been filtered in 3.4.5
Let's set up a catalog! Arbitrary name
At this time, we uploaded files and found that upload jpg gif format is not good, but txt can upload, command XX.ASP;.TXT can not upload
You have to be flexible and upload it on XX.CER;.txt.
The repair method is nothing more than fixing the parsing and folder read and write permissions http://www.2cto.com/Article/201203/122038.html of iis6.0.