The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Trio of bugs bite MS Content Management Server
Time: 03:22 EST/08:22 GMT | News Source: The Register | Posted By: Alex Harris

A trio of vulnerabilities in Microsoft's Content Management Server (MCMS) has come to light, the most serious of which potentially allows attackers to gain control of victim's machines. Microsoft has issued a patch - which Redmond characterises as of "critical importance" - designed to fix the problem with Content Management Server 2001 software, Redmond's product for the development and management of e-business Web sites.

First up, and most seriously, there's a buffer overrun flaw in a low-level function that performs user authentication in MCMS 2001. The result of exploiting this vulnerability would be to either cause MCMS to fail, or run code in the context of the MCMS service (which runs as Local System). Next there's a SQL injection vulnerability affecting a function that services requests for image files and other resources. Exploiting this flaw could enable an attacker to run SQL commands on the server, which would "not only allow data in the MCMS database to be added, changed or deleted, but would also enable the attacker to run operating system commands on the server," Microsoft admits.

Write Comment
Return to News

  Displaying 301 through 301 of 301
Prev | First
  The time now is 4:59:38 PM ET.
Any comment problems? E-mail us
#301 By 4240821 (62.76.153.72) at 11/24/2024 12:22:44 AM
https://justpaste.me/BdKG5
https://justpaste.me/BiMQ1
https://justpaste.me/CENs3
https://justpaste.me/CVjO
https://justpaste.me/C97s
https://justpaste.me/Bg8x2
https://justpaste.me/CG8J2
https://justpaste.me/CEjY6
https://justpaste.me/CYC21
https://justpaste.me/CKGJ2

Write Comment
Return to News
  Displaying 301 through 301 of 301
Prev | First
  The time now is 4:59:38 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *