NetServe Web Server Multiple Security Vulnerabilities
12 Jul. 2011
Summary
NetServe Web Server is prone to multiple security vulnerabilities including multiple cross-site scripting, remote file-inclusion, local file-inclusion, script-insertion, HTML-injection, and denial-of-service vulnerabilities.
Vulnerable Systems:
*Net-X Solutions NetServe Web Server 1.0.58
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, to upload arbitrary files onto the webserver, execute arbitrary remote and local files within the context of the webserver, obtain sensitive information, steal cookie-based authentication credentials, and deny service to legitimate users. Other attacks are also possible.
Vendor Status:
Currently we are not aware of any vendor-supplied patches