Interesting article on the origins of the tea party
10 posts • joined 19 Jun 2009
The issue isn't really anything to do with the criterium for "executable by webserver" is the three-letter file ending.
The problem is people setting up a folder to hold user generated content under the web site root (as it needs to be served by the web server) but forgetting to deny IIS execute access for scripts on that folder. Maybe as they figured that it could only hold innocuous content anyway.
I've only used IIS 4 - 6 so maybe this has been improved in IIS7 but forgetting to reproduce these permissions is too easy to do when creating new sites by XCopy.
Biting the hand that feeds IT © 1998–2021