Security Risks on ASP Based Shared Servers
Basically, the security on shared windows servers, supporting ASP, is not very high. A simple problem, with large consequences is file security.
Let's say, user X can upload ASP pages to the directory /User/X. User Y has the same hosting package and can upload to /User/Y. Most hosts just create an FTP account for every user, pointing them to there own directory. So far, so good. Every user can upload there nice websites into there own directory.
But then, the FileSystemObject comes into the picture. Let's say user X has a file /user/X/index.asp which contains all sorts of information, but noone but him is supposed to reach the code.