CVE-2009-3561
Xerver HTTP Server 4.32 - Path Traversal via chooseDirectory currentPath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3561. PoCs published by Stack.
AI-analyzed exploit summary The exploit demonstrates a directory traversal and XSS vulnerability in Xerver HTTP Server v4.32. The directory traversal allows accessing arbitrary files by manipulating the 'currentPath' parameter, while the XSS is triggered via script injection in the same parameter.
Description
Directory traversal vulnerability in Xerver HTTP Server 4.32 allows remote attackers to read arbitrary files via a full pathname with a drive letter in the currentPath parameter in a chooseDirectory action.
Exploits (1)
The exploit demonstrates a directory traversal and XSS vulnerability in Xerver HTTP Server v4.32. The directory traversal allows accessing arbitrary files by manipulating the 'currentPath' parameter, while the XSS is triggered via script injection in the same parameter.