TIP: Click on subject to list as thread! ANSI
echo: nthelp
to: Geo
from: Mike N.
date: 2006-07-14 06:48:24
subject: Re: July patches

From: Mike N. 

On Fri, 14 Jul 2006 06:09:19 -0400, "Geo"  wrote:

>Depending on how the site works, anything that allows
>a web visitor to post unchecked text and then view that text as a web page
>could possibly be used to exploit this if they can get the server to
>interpret that text.

   This would be the equivalent of allowing the forum users to upload .ASP
pages.   It would have to be a big hole in the forum software.   The next
closest thing would be some sort of Server Side Include, but it's not clear
that this could trigger the .ASP vulnerability.

--- BBBS/NT v4.01 Flag-5
* Origin: Barktopia BBS Site http://HarborWebs.com:8081 (1:379/45)
SEEN-BY: 633/267 270 5030/786
@PATH: 379/45 1 106/2000 633/267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.