The information in this article applies to:
SYMPTOMSServer Side Includes (SSI) can pose a security threat to any web server. If executable SSI are enabled on a server that contains a FrontPage feedback form, the security threat will be increased. This security threat occurs under specific conditions as described in the "More Information" section of this article. CAUSEThe FrontPage Server Extensions enable you to write HyperText Markup Language (HTML) from a Web browser into a form and have it accurately evaluated by the Web server. RESOLUTION
Microsoft strongly recommends that you disable executable SSI on any
server on which you have installed the FrontPage Server Extensions.
http://www.microsoft.com/frontpage/wpp/exts.htmThe updated FrontPage Server Extensions will not allow HTML tags in any feedback form. Instead, the FrontPage Server Extensions will convert the HTML tags into the corresponding character entities that represent the code. For example, the less than sign (<) will be converted to < and the greater than sign (>) will be converted to >. This allows you to enter the HTML code into the feedback form. When you browse the form, the code will appear exactly as you typed it when you filled out the feedback form. STATUSMicrosoft has confirmed this to be a problem in the Microsoft FrontPage Server Extensions version 2.0.2.1112. This problem was corrected in Microsoft FrontPage Server Extensions version 2.0.3.209. MORE INFORMATION
Any web site that uses the FrontPage Server Extensions and where the
results from a WebBot Discussion component, WebBot Confirmation component, or
WebBot Save Results component are saved to a public HTML page, such as a guest
book, can be compromised by server-side executable commands entered into a
feedback form.
Additional query words: 97
Keywords : kbusage kbdta fpext |
Last Reviewed: July 23, 1999 © 2000 Microsoft Corporation. All rights reserved. Terms of Use. |