CVE-2009-3562
Xerver HTTP Server 4.32 - Cross-Site Scripting via currentPath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3562. PoCs published by Stack.
AI-analyzed exploit summary The exploit demonstrates a directory traversal and XSS vulnerability in Xerver HTTP Server v4.32. The directory traversal allows accessing arbitrary files by manipulating the 'currentPath' parameter, while the XSS is triggered via script injection in the same parameter.
Description
Cross-site scripting (XSS) vulnerability in Xerver HTTP Server 4.32 allows remote attackers to inject arbitrary web script or HTML via the currentPath parameter in a chooseDirectory action.
Exploits (1)
The exploit demonstrates a directory traversal and XSS vulnerability in Xerver HTTP Server v4.32. The directory traversal allows accessing arbitrary files by manipulating the 'currentPath' parameter, while the XSS is triggered via script injection in the same parameter.