Main > Utilities > Patches and Updates >

Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1

Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1

Sponsored Links

Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1 Ranking & Summary

RankingClick at the star to rank
Ranking Level
User Review: 0 (0 times)
File size: 1K
Platform: Windows 9X/ME/NT/2K/2003/XP/Vista
License: Freeware
Price:
Downloads: 3536
Date added: 2000-02-19
Publisher: Microsoft

Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1 description

Microsoft has released a patch that eliminates a security vulnerability in web applications associated with Microsoft® Site Server 3.0, Commerce Edition. These applications are provided as samples and generated by wizards, but do notfollow security best practices. If deployed on a web site, they could allow inappropriate access to a database on the site. Two sample web sites provided as part of Site Server 3.0, Commerce Edition do not follow security best practices;the code generated by one of the wizards is affected by the same problem. The code requests an identification number as one of the inputs, but does not validate it before using it ina database query. As a result, a malicious user could, instead of entering an appropriate input, provide SQL commands. If this were done, the SQL commands would be executed as part of the query, and could be used to create, modify, delete or read data in the database. The vulnerability only affects sites that have either deployed the code at issue here, or have used the code as a model for developingcustom code. Customers who have deployed the code should apply the patch to ensure that security best practices are followed.

Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1 Screenshot

Advertisements

Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1 Keywords

Bookmark Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1

Hyperlink code:
Link for forum:

Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1 Copyright

WareSeeker periodically updates pricing and software information of Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1 full version from the publisher, so some information may be slightly out-of-date. You should confirm all information before relying on it. Software piracy is theft, Using crack, password, serial numbers, registration codes, key generators is illegal and prevent future development of Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1 Edition. Download links are directly from our publisher sites, torrent files or links from rapidshare.com, yousendit.com or megaupload.com are not allowed

Allok Video Splitter 2.2.0 Review:

Name (Required)
Email(Required)
Captcha
Featured Software

Want to place your software product here?
Please contact us for consideration.

Contact WareSeeker.com
Related Software
Microsoft Security Bulletin MS00-012 announces the availability of a patch that eliminates a vulnerability in Microsoft Systems Management Server (SMS). If the Remote Control feature of SMS has been i Free Download
Microsoft has released a patch that eliminates a security vulnerability in the Microsoft® virtual machine (Microsoft VM). The vulnerability could enable a malicious web site operatorto read files fro Free Download
Microsoft has released a patch that eliminates two security vulnerabilities in Microsoft® Internet Explorer. The vulnerabilities involve how IE handles digital certificates; under a very daunting set Free Download
Microsoft has released a patch that eliminates a security vulnerability in the Microsoft® Clip Art Gallery. The vulnerability could allow a malicious party to cause hostile code to execute on the com Free Download
If a specially-malformed TDS packet is sent to a SQL server, it can cause the SQL service to crash. This vulnerability would not allow any inappropriate access to the data on the server, nor would it Free Download
Secure your server and better it defend against hackers Free Download
Microsoft has released a patch that eliminates a securityvulnerability in Microsoft® SQL Server® 7.0Service Packs 1 and 2 installation routine. Whenrun on a machine that is configured in a non-recom Free Download
Gain access to critical business communications almost whenever and wherever Free Download