Web Hack List

Other nomination

IIS6/ASP & file upload for fun and profit

IIS 6 decides whether ASP.dll should execute a request by scanning URL segments for executable extensions, so a directory named folder.asp makes IIS run any file beneath it - folder.asp/document.pdf executes as ASP. Combined with CVE-2009-4444 semicolons and NTFS alternate data streams (file.asp::$DATA, filename.asp:.jpg), it defeats extension filters in third-party upload components.

Record

Researcher
Juan Galiana

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Juan Galiana, first published at the original source. Preserved copies are kept so the citation survives its host.