vendor:
Xerver web server
by:
Ben Schmidt aka supernothing
7,5
CVSS
HIGH
Source Code Disclosure/Download, Authentication Bypass
N/A
CWE
Product Name: Xerver web server
Affected Version From: 4.32 and prior
Affected Version To: 4.32 and prior
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2010
Xerver Source Disclosure and HTTP Auth Bypass
This module exploits a source code disclosure/download vulnerability in versions of the Xerver web server up to and including version 4.32. It also incorporates an authentication bypass vulnerability that allows you to dump the source of files in HTTP auth protected directories as well.
Mitigation:
Upgrade to the latest version of Xerver web server