Vulnerability Development mailing list archives

FrontPage Server Extension : fp30reg.dll Cross Site Scripting


From: "Brett Moore" <brett () softwarecreations co nz>
Date: Tue, 7 May 2002 19:24:36 +1200

Hi.
        I have a win 2000 server that has the latest patch for IIS.

        I think it has the patch for FrontPage Server Extension Sub-Component
Contains Unchecked Buffer. As I have checked the overflow length and it does
not have an effect.
        That was the only patch I could find for this dll, so is this an unknown.

        request <server>/_vti_bin/_vti_aut/fp30reg.dll?<usual css stuff>

        I don't have other servers to check it on, and so would appreciate any
feedback as to if this affects others, or if there is a patch for this
issue?

Regards

Brett


Current thread: