I came upon a public Library Administration Module on Microsoft's MacTopia website. The page (which you could see at the above picture), which was also listed on Microsoft's search engine, allowed users to modify information within different MacTopia libraries. The page contained options on which library to post to, date set options for the page to expire, urls, etc. ZDNet and ActiveWin.com promptly notified Microsoft of the security hole and Microsoft removed it immediately upon our notification. The page can still be found at MS Search (again, it has been removed):
"http:// www.microsoft.com / MAC / library / Administration / AddRecord.asp"
Summary: MacTopia Library Administration Page New Records Headline: Sub-Heading: 255 characters max! No. of Pages: URL's Page 1: Page 2: Page 3: Page 4: Placement: 1 Home 1 Business
Category = Products: MAC
Again, you can see a pic of the page at the above URL.
|