Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8147413
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 6, 20262026-06-06T14:20:41+00:00 2026-06-06T14:20:41+00:00

Sorry is this is not the correct forum to post this, but I’m running

  • 0

Sorry is this is not the correct forum to post this, but I’m running out of ideas here. We have recently purchased a new dedicated server (running Windows Web Server 2008 R2). One of our customers to trying to obtain PCI Compliance. The server is up to date and we have closed all unneeded ports and loophole. But the site keep failing one of there tests. I’ll paste the failure message:


Title: vulnerable web program (Singapore) Impact: A remote attacker could execute arbitrary commands, create or overwrite files, or view files or directories on the web server.

Data Sent:

GET /thumb.php?image=../data/users.csv.php%00.jpg
HTTP/1.0 Host: www.monorep.co.uk
User-Agent: Mozilla/4.0
Connection: Keep-alive

Data Received:

And: <html xmlns="http://www.w3.org/1999/xhtml"><!-- InstanceBegin template="/Templates/standard page - group.dwt.aspx" codeOutsideHTMLIsLocked="false" -->
And: <a class="addthis_button_email"></a> Resolution: 12/23/04 CVE 2004-1407 CVE 2004-1408 CVE 2004-1409 CVE 2006-3194 CVE 2006-3195 CVE 2006-3196

The Singapore image gallery application is affected by multiple vulnerabilities. Singapore 0.10 and earlier are affected by these vulnerabilities: Directory traversal in index.php allowing unauthorized read access to sensitive files in the application's directory, such as the users.csv.php file which contains encrypted passwords Cross-site scripting in index.php Ability to obtain installation path Singapore 0.9.10 and earlier are affected by these vulnerabilities. Directory traversal in thumb.php allowing unauthorized read access to sensitive files in the application's directory, such as the users.csv.php file which contains encrypted passwords File upload vulnerability in addImage function allowing logged-on users to upload and execute PHP scripts Directory traversal allowing deletion of arbitrary directories on Windows platforms if the web server has write access to the directory Cross-site scripting Resolution: Upgrade to Singapore 0.10.1 or higher when available.

Risk Factor: High/ CVSS2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVE: CVE-2004-1408 BID: 11990 18518 Additional CVEs: CVE-2006-3194
CVE-2006-3196 CVE-2004-1409 CVE-2004-1407 CVE-2006-3195


I’ve got no idea what this is on about. We don’t use this “Singapore” application and we do not run php at all on the server.

Could anybody offer any suggestions on this one please. I would be monster grateful for any advice offers.

Thanks.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-06T14:20:42+00:00Added an answer on June 6, 2026 at 2:20 pm

    PCI security scanners are simple software with large databases. They are intended to provide inspiration for securing a system, but it is up to humans to follow up on any items found. Discuss anything that you cannot resolve with the assessor and evaluate whether the scan results could represent genuine security risks in your environment.

    That said, the least effort way through the assessment procedure tends to be based on a minimal surface area and clean security scans, of course.

    To be useful also with software that was never seen before, the scanners check for suspect behavior rather than for known bad software versions. On the other hand, to give you practical guidance, they attempt to point to a component that the suspect behavior could be associated with, to encourage full available security patching (removal, upgrade) rather than dealing with the detected faulty behaviors one by one.

    Of course you were never running Singapore whatever that was. The problem here is that your configuration of IIS seems to allow two problematic things:

    • Allow .. in HTTP requests to access files outside of configured folders
    • Serve paths that look like images (.jpg) to the web server, but are eventually referencing something much more sensitive because of a C++-style string terminator (MIME encoded as %00) inserted in the path.

    Read more about the former issue here. Read here how to turn parent paths on and off. (Parent paths are off by default in IIS 7 and if you did not change that, this Singapore item is a completely bogus alarm.)

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Sorry if this has already been answered but I could not find it here.
NOTE: sorry as this is not a programming question but i am not aware
Sorry this is probably super basic. But in all my javabean examples, I've not
First of I'm very sorry but this questions is not so so specific. All
Sorry if this question is too vague, but I'd rather not muddy it's point
Sorry if this question sounds a little silly, but I am not sure what
I am sorry if this is a duplicate but I was not able to
I'm very sorry if I'm wording this wrong in advance but I have a
Sorry, I wasn't sure exactly what title to give this and have not been
Sorry this question is not very clear, if I know the correct words to

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.