ASPXSpy.Detection

Release DateMar 31, 2009
SeverityLow
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates a potential .NET ASP webshell upload. A malicious user may use this script to further compromise the targeted host.
Affected ProductsN/A
Recommended ActionsConfigure a Worker Process Identity (WPI) for an application pool.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1436
Reference/shttp://www.vupen.com/english/advisories/2008/1264 (FrSIRT)
http://www.milw0rm.com/exploits/6705
Reference: VID-15558