Patch Day - July 2006
Pretty interesting month as we see two IIS related security bulletins. Again, not IIS core engine, both are components thta sit on top of the IIS server. Oh well, you can argue that for the asp.dll, it was part of the IIS built-in component :)
MS06-033: Vulnerability in ASP.NET Could Allow Information Disclosure (917283)
Severity: Important
http://www.microsoft.com/technet/security/Bulletin/MS06-033.mspx
Only affecting - .NET Framework 2.0
MS06-034: Vulnerability in Microsoft Internet Information Services using
Active Server Pages Could Allow Remote Code Execution (917537)
Severity: Important
http://www.microsoft.com/technet/security/Bulletin/MS06-034.mspx
If you are using ASP for IIS 5.0, 5.1 and 6.0
For complete July security bulletins, refer here.