IIS volunrability scan results

From: Juan B (juanbabi_at_yahoo.com)
Date: 12/22/04

  • Next message: Marty: "Wireless security question"
    Date: Wed, 22 Dec 2004 06:36:47 -0800 (PST)
    To: security-basics@securityfocus.com
    
    

    HI,

    I ran whcc against one of my company's web site (IIS).

    this is what I reciecved:

    Exploit: /./
    Description: Appending '/./' to a directory may reveal
    php source code.

    Exploit: /?sql_debug=1
    Description: The PHP-Nuke install may allow attackers
    to enable debug mode and disclose sensitive
    information by adding sql_debug=1 to the query string.

    Exploit: /?"><script>alert("Vu

    is this critical? can some one please expain or give
    some links so Ican understand those results?

    thanks very much !

            
                    
    __________________________________
    Do you Yahoo!?
    Yahoo! Mail - You care about security. So do we.
    http://promotions.yahoo.com/new_mail


  • Next message: Marty: "Wireless security question"

    Relevant Pages

    • RE: write permissions for IIS
      ... I found free and pay solutions for this, ... > Subject: write permissions for IIS ... > given write permissions to a directorz that is readable from the web. ... Do You Yahoo!? ...
      (Focus-Microsoft)
    • Re: http_head from w2k/win98
      ... > connection is trying to use a http_head. ... > There was a suggestion that this could be code blue. ... > systems do not have IIS. ... > Make a great connection at Yahoo! ...
      (Security-Basics)
    • Re: scripting MAJOR HELP ASAP
      ... I don't think Yahoo even use IIS for this service, ... > and i have a secured directory and i want to set it up so when someone> logs in with a username and password...depending on their username it> takes them to a different directory/page... ...
      (microsoft.public.inetserver.iis)
    • Re: Error while applying iislockdown
      ... > Which version of IIS you are using? ... >> Do you Yahoo!? ... Modeled after the famous Black Hat event in ... tracks, 12 training sessions, top speakers and sponsors. ...
      (Security-Basics)