HTTP: Microsoft FrontPage 2000 ASP File Upload Vulnerability

This signature detects attempts to exploit a known flaw in FrontPage 2000. Unauthenticated attackers can upload server-side ASP scripts, resulting in arbitrary code execution on the server.

Extended Description

A file upload vulnerability allegedly affects the DATA Access Internet Publishing Service Provider Distributed Versioning and Authoring (DAV) functionality of Microsoft FrontPage 2000. An attacker may leverage this issue to upload arbitrary files to the affected computer. This will allow the execution of server-based script code, and will facilitate a compromise of the affected server. Depending on the purpose on the server, an attacker could also exploit the issue to place malicious or abuse content on the server. It should be noted that the individual reporting this issue may have discovered it while auditing a poorly configured implementation of the affected software; if this were the case this issue may not be a vulnerability. This BID will be updated immediately upon the release of new information.

Affected Products

Microsoft frontpage_2000

Short Name
HTTP:EXPLOIT:FP2K-ASP-UPLOAD
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
2000 ASP CVE-2015-6922 File FrontPage Microsoft Upload Vulnerability bid:12141
Release Date
11/16/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Microsoft

CVSS Score

7.5

Found a potential security threat?