Article ID: 189272
Article Last Modified on 9/28/2005
APPLIES TO
- Microsoft Internet Information Server 4.0
This article was previously published under Q189272
We strongly recommend that all users upgrade to Microsoft Internet Information Services (IIS) version 6.0 running on Microsoft Windows Server 2003. IIS 6.0 significantly increases Web infrastructure security. For more information about IIS security-related topics, visit the following Microsoft Web site:
SUMMARY
A computer running Internet Information Server (IIS) may be vulnerable to
attack if the following conditions are true:
- IIS is configured to allow users to upload content using RFC 1867
methods.
- The directory that users can upload to has both Write access and
Execute permissions.
Additional query words: ACL ACLs privileges hack hackers #exec Executable Content
Keywords: kbinfo KB189272