I got the message below off my snort IDS system I'm running is this true? I ran IIS lock down and just gave write rights to the *.mdb. And I have the IIS box patched. Just want to make sure I'm not missing anything:) Here is the link too.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
http://www.snort.org/snort-db/sid.html?sid=2134
Snitz Forums is an Active Server Page (asp) application running on Microsoft Internet Information Server. A vulnerability exists in Snitz Forums that can allow an attacker to inject SQL code of his choice into the application. The file register.asp contains a flaw that can allow an attacker to gain administrator access to the site.
The attacker may be trying to gain administrator access to the host, garner information on users of the system, retrieve sensitive information or be attempting to execute arbitrary code.
Disregard THIS just don't use Snitz:) he he
Edited by lodogg