Free Downloads Center
e.g. Microsoft Site Server 3.0 'Site Wizard Input Validation' Vulnerability patch 1

Categories

Latest Reviews

DetachPipe

DetachPipe
DetachPipe is a completely reliable email attachment management solution for Microsoft Outlook.

Acebyte Utilities Free

Acebyte Utilities Free
Keep your system stable and smooth with this set of powerful utilities from, Acebyte Utilities Free.

Subscribe

Microsoft Site Server 3.0 'Site Wizard Input Validation' Vulnerability patch 1 Download

Editor's rating  
Users' rating   (0 votes) Rate it!
License Freeware /
Downloads 81
Publisher
File size 1K
Date added 19-Feb-2000
Microsoft Site Server 3.0 'Site Wizard Input Validation' Vulnerability patch screenshot

Enlarge screenshot

Publisher's description
Submit your review

Microsoft has released a patch that eliminates a security vulnerability in web applications associated with Microsoft® Site Server 3.0, Commerce Edition. These applications are provided as samples and generated by wizards, but do notfollow security best practices. If deployed on a web site, they could allow inappropriate access to a database on the site. Two sample web sites provided as part of Site Server 3.0, Commerce Edition do not follow security best practices;the code generated by one of the wizards is affected by the same problem. The code requests an identification number as one of the inputs, but does not validate it before using it ina database query. As a result, a malicious user could, instead of entering an appropriate input, provide SQL commands. If this were done, the SQL commands would be executed as part of the query, and could be used to create, modify, delete or read data in the database. The vulnerability only affects sites that have either deployed the code at issue here, or have used the code as a model for developingcustom code. Customers who have deployed the code should apply the patch to ensure that security best practices are followed.

Visit homepage of Microsoft Site Server 3.0 'Site Wizard Input Validation' Vulnerability patch

Download Microsoft Site Server 3.0 'Site Wizard Input Validation' Vulnerability patch 1



Programs related to Microsoft Site Server 3.0 'Site Wizard Input Validation' Vulnerability patch

Copyright © 2001-2011, Free Downloads Center.