ID

VAR-E-201004-1346


TITLE

Mini Web Server Cross Site Scripting and Directory Traversal Vulnerabilities

Trust: 0.3

sources: BID: 39780

DESCRIPTION

Mini Web Server is prone to a directory-traversal vulnerability and a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting these issues will allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, and to view arbitrary local files and directories within the context of the webserver. This may let the attacker steal cookie-based authentication credentials and other harvested information may aid in launching further attacks.
Mini Web Server 1.0 is vulnerable; other versions may also be affected.

Trust: 0.3

sources: BID: 39780

AFFECTED PRODUCTS

vendor:minimodel:web server mini web serverscope:eqversion:1.0

Trust: 0.3

sources: BID: 39780

EXPLOIT

Attackers can exploit the cross-site scripting issue by enticing an unsuspecting victim to follow a malicious URI.
The following example data and URI are available:
GET %00"><font color=red>Work?</font><" HTTP/1.1
http://www.example.com/%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c1.txt

Trust: 0.3

sources: BID: 39780

PRICE

Free

Trust: 0.3

sources: BID: 39780

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 39780

CREDITS

cp77fk4r

Trust: 0.3

sources: BID: 39780

EXTERNAL IDS

db:BIDid:39780

Trust: 0.3

sources: BID: 39780

REFERENCES

url:http://www.jibble.org/miniwebserver/

Trust: 0.3

sources: BID: 39780

SOURCES

db:BIDid:39780

LAST UPDATE DATE

2022-07-27T09:33:28.911000+00:00


SOURCES UPDATE DATE

db:BIDid:39780date:2010-04-28T00:00:00

SOURCES RELEASE DATE

db:BIDid:39780date:2010-04-28T00:00:00