CVE-2013-2181: XSS
Published Jul 29, 2013
·Updated
Cross-site scripting (XSS) vulnerability in the Directory Listing plugin in Monkey HTTP Daemon (monkeyd) 1.2.2 allows attackers to inject arbitrary web script or HTML via a file name.
Affected Software
1 affected component
Monkey-project Monkey=1.2.2
Event History
Jul 29, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2181?
CVE-2013-2181 is considered a medium risk vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2013-2181?
To mitigate CVE-2013-2181, upgrade to a patched version of the Monkey HTTP Daemon that addresses this XSS vulnerability.
3
What is the impact of CVE-2013-2181?
The impact of CVE-2013-2181 allows attackers to execute arbitrary web scripts or HTML on affected installations, potentially compromising user data.
4
Which software versions are affected by CVE-2013-2181?
CVE-2013-2181 specifically affects Monkey HTTP Daemon version 1.2.2.
5
Is CVE-2013-2181 exploitable remotely?
Yes, CVE-2013-2181 is exploitable remotely as it allows attackers to inject code through crafted file names.