.. / CVE-2006-1681

Exploit for Cherokee HTTPD <=0.5 - Cross-Site Scripting (CVE-2006-1681)

Description:

Cherokee HTTPD 0.5 and earlier contains a cross-site scripting vulnerability which allows remote attackers to inject arbitrary web script or HTML via a malformed request that generates an HTTP 400 error, which is not properly handled when the error message is generated.

Nuclei Template

View the template here CVE-2006-1681.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2006/CVE-2006-1681.yaml
Copy

References:

https://security.gentoo.org/glsa/202012-09
https://exchange.xforce.ibmcloud.com/vulnerabilities/25698
https://nvd.nist.gov/vuln/detail/CVE-2006-1681
http://www.vupen.com/english/advisories/2006/1292