Xerver Multiple Vulnerabilities
BID:42110
Info
Xerver Multiple Vulnerabilities
| Bugtraq ID: | 42110 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 01 2010 12:00AM |
| Updated: | Aug 01 2010 12:00AM |
| Credit: | Ben Schmidt |
| Vulnerable: |
Xerver Xerver 4.32 |
| Not Vulnerable: | |
Discussion
Xerver Multiple Vulnerabilities
Xerver is prone to multiple vulnerabilities including source code disclosure, denial of service, security bypass, and directory-traversal issues.
Successfully exploiting these issues may allow an attacker to disclose sensitive information, bypass certain security-restrictions, perform denial-of-service attacker or execute arbitrary binaries.
These issues affect Xerver versions up to and including 4.32.
Xerver is prone to multiple vulnerabilities including source code disclosure, denial of service, security bypass, and directory-traversal issues.
Successfully exploiting these issues may allow an attacker to disclose sensitive information, bypass certain security-restrictions, perform denial-of-service attacker or execute arbitrary binaries.
These issues affect Xerver versions up to and including 4.32.
Exploit / POC
Xerver Multiple Vulnerabilities
These issues can be exploited through a web client.
The following exploit code is available.
These issues can be exploited through a web client.
The following exploit code is available.
Solution / Fix
Xerver Multiple Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Xerver Multiple Vulnerabilities
References:
References:
- Home page (Xerver)
- Multiple vulnerabilities in Xerver 4.32 (Spare Clock Cycles.org)