This application requires Javascript for optimal performance.

MS.FrontPage.Server.Extensions.RPC.File.Upload

Release Date

Jan 05, 2012

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against an Arbitrary File Uploading vulnerability in Microsoft Frontpage Server Extentisons.

The vulnerability is caused by the "put document" function. By sending a specially crafted HTTP POST request to the "put document" method involved in author.dll, a remote attacker could upload file on a vulnerable system.

Affected Products

IIS 5.x with Frontpage Server Extentions

Recommended Actions

Currently we are not aware of any vendor supplied patch for this issue.

Coverage

IPS
VCM

Reference/s

http://msdn.microsoft.com/en-us/library/dd587467(v=office.11).aspx
http://msdn.microsoft.com/en-us/library/ms443099.aspx
http://msdn.microsoft.com/en-us/library/dd586281(v=office.11).aspx

Reference: VID-30579