>> Microsoft Internet Information Services Code Execution Vulnerability (MS06-034)
Title : Microsoft Internet Information Services Code Execution Vulnerability (MS06-034) VUPEN ID : VUPEN/ADV-2006-2752 CVE ID : CVE-2006-0026
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-07-11
Technical Description
A vulnerability has been identified in Microsoft Internet Information Services (IIS), which could be exploited by attackers to compromise a vulnerable server. This flaw is due to a buffer overflow error when processing malformed Active Server Pages (ASP), which could be exploited by an attacker who can upload a malicious "ASP" page to execute arbitrary commands with the privileges of the web server.