Vulnerabilities > CVE-2005-1659

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
myserver
nessus

Summary

Cross-site scripting (XSS) vulnerability in filemanager.cpp in MyServer 0.8 allows remote attackers to inject arbitrary Javascript via a URL with a "..." (triple dot) followed by an onmouseover event.

Vulnerable Configurations

Part Description Count
Application
Myserver
1

Nessus

NASL familyCGI abuses
NASL idMYSERVER_DIR_LIST_AND_XSS.NASL
descriptionThe remote host is running MyServer, an open source http server. This version is vulnerable to a directory listing flaw and cross-site scripting. An attacker can execute a cross-site scripting attack, or gain knowledge of certain system information of the server.
last seen2020-06-01
modified2020-06-02
plugin id18218
published2005-05-10
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/18218
titleMyServer 0.8 Multiple Vulnerabilities