>> Xerox WorkCentre Pro MicroServer Web Server Vulnerabilities
Title : Xerox WorkCentre Pro MicroServer Web Server Vulnerabilities VUPEN ID : VUPEN/ADV-2005-1009 CVE ID : CVE-2005-2200 - CVE-2005-2201 - CVE-2005-2202 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-07-07
Technical Description
Multiple vulnerabilities were identified in Xerox WorkCentre Pro MicroServer Web Server, which could be exploited by malicious users to conduct cross site scripting and denial of service attacks or gain unauthorized access.
The first issue is due to an unspecified error in the authentication procedure, which could be exploited by attackers to gain unauthorized access.
The second flaw is due to an error when processing specially crafted HTTP requests, which could be exploited by attackers to gain unauthorized access or cause a denial of service.
The third vulnerability is due to an input validation error when processing specially crafted parameters, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser.