Main > Utilities > Patches and Updates >

Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1



 

Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1

Sponsored Links

Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1 Ranking & Summary

RankingClick at the star to rank
Ranking Level
User Review: 0 (0 times)
File size: 1K
Platform: Windows 9X/ME/NT/2K/2003/XP/Vista
License: Freeware
Price:
Downloads: 3536
Date added: 2000-02-19
Publisher: 5am Code

Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1 description

Microsoft has released a patch that eliminates a security vulnerability in web applications associated with Microsoft® Site Server 3.0, Commerce Edition. These applications are provided as samples and generated by wizards, but do notfollow security best practices. If deployed on a web site, they could allow inappropriate access to a database on the site. Two sample web sites provided as part of Site Server 3.0, Commerce Edition do not follow security best practices;the code generated by one of the wizards is affected by the same problem. The code requests an identification number as one of the inputs, but does not validate it before using it ina database query. As a result, a malicious user could, instead of entering an appropriate input, provide SQL commands. If this were done, the SQL commands would be executed as part of the query, and could be used to create, modify, delete or read data in the database. The vulnerability only affects sites that have either deployed the code at issue here, or have used the code as a model for developingcustom code. Customers who have deployed the code should apply the patch to ensure that security best practices are followed.

Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1 Screenshot

Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1 Keywords

Bookmark Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1

Hyperlink code:
Link for forum:

Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1 Copyright

WareSeeker.com do not provide cracks, serial numbers etc for Microsoft Site Server 3.0 Site Wizard Input Validation Vulnerability patch 1. Any sharing links from rapidshare.com, yousendit.com or megaupload.com are also prohibited.

Allok Video Splitter 2.2.0 Review:

Name (Required)
Email(Required)
Captcha
Featured Software

Want to place your software product here?
Please contact us for consideration.

Contact WareSeeker.com
Related Software
Microsoft Security Bulletin MS00-012 announces the availability of a patch that eliminates a vulnerability in Microsoft Systems Management Server (SMS). If the Remote Control feature of SMS has been i Free Download
Microsoft has released a patch that eliminates a security vulnerability in the Microsoft® virtual machine (Microsoft VM). The vulnerability could enable a malicious web site operatorto read files fro Free Download
Microsoft has released a patch that eliminates two security vulnerabilities in Microsoft® Internet Explorer. The vulnerabilities involve how IE handles digital certificates; under a very daunting set Free Download
Microsoft has released a patch that eliminates a security vulnerability in the Microsoft® Clip Art Gallery. The vulnerability could allow a malicious party to cause hostile code to execute on the com Free Download
If a specially-malformed TDS packet is sent to a SQL server, it can cause the SQL service to crash. This vulnerability would not allow any inappropriate access to the data on the server, nor would it Free Download
Secure your server and better it defend against hackers Free Download
Microsoft has released a patch that eliminates a securityvulnerability in Microsoft® SQL Server® 7.0Service Packs 1 and 2 installation routine. Whenrun on a machine that is configured in a non-recom Free Download
Gain access to critical business communications almost whenever and wherever Free Download