Auto Directory Index Cross-Site Scripting Vulnerabilities
16 Nov. 2003
Summary
AutoIndex is "a project whose goal is to create a "Windows Explorer" that can be used to browse through folders on websites", a cross site scripting vulnerability in the product allows remote attackers to inject arbitrary HTML and or JavaScript into the web pages returned by the product.
Vulnerable systems:
* Auto Directory Index version 1.2.3 and prior
The vulnerability is caused due to missing validation of input supplied to the "dir" parameter. This can be exploited by including arbitrary HTML or script code in the parameter, which will cause it to be executed in a user's browser session when viewed.