CVE-2009-3562

Xerver HTTP Server 4.32 - Cross-Site Scripting via currentPath Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-3562. PoCs published by Stack.

AI-analyzed exploit summary The exploit demonstrates a directory traversal and XSS vulnerability in Xerver HTTP Server v4.32. The directory traversal allows accessing arbitrary files by manipulating the 'currentPath' parameter, while the XSS is triggered via script injection in the same parameter.

Description

Cross-site scripting (XSS) vulnerability in Xerver HTTP Server 4.32 allows remote attackers to inject arbitrary web script or HTML via the currentPath parameter in a chooseDirectory action.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Stack · textremotemultiple
https://www.exploit-db.com/exploits/9718

The exploit demonstrates a directory traversal and XSS vulnerability in Xerver HTTP Server v4.32. The directory traversal allows accessing arbitrary files by manipulating the 'currentPath' parameter, while the XSS is triggered via script injection in the same parameter.

Classification
Working Poc 90%
Attack Type
Xss | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Xerver HTTP Server v4.32
No auth needed
Prerequisites: Network access to the target server · Xerver HTTP Server v4.32 running
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36681
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/36457
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9718

Scores

EPSS 0.0149
EPSS Percentile 70.6%

Details

CWE
CWE-79
Status published
Products (1)
xerver/xerver 4.32
Published Oct 05, 2009
Tracked Since Feb 18, 2026