Xedus Webserver Multiple XSS

medium Nessus Plugin ID 14647

Synopsis

The remote host is running a web server with a cross-site scripting vulnerability.

Description

The remote host runs Xedus Peer-to-Peer web server.
This version is vulnerable to cross-site scripting attacks.

With a specially crafted URL, an attacker can cause arbitrary code execution resulting in a loss of integrity.

Solution

Upgrade to the latest version and remove .x files located in ./sampledocs folder

See Also

http://www.nessus.org/u?7d859f3a

Plugin Details

Severity: Medium

ID: 14647

File Name: xedus_xss.nasl

Version: 1.27

Type: remote

Published: 9/3/2004

Updated: 6/12/2020

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.8

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 8/30/2004

Reference Information

CVE: CVE-2004-1645

BID: 11071

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990

Secunia: 12418