Vulnerabilities > Xerver

DATE CVE VULNERABILITY TITLE RISK
2009-10-05 CVE-2009-3562 Cross-Site Scripting vulnerability in Xerver 4.32
Cross-site scripting (XSS) vulnerability in Xerver HTTP Server 4.32 allows remote attackers to inject arbitrary web script or HTML via the currentPath parameter in a chooseDirectory action.
network
high complexity
xerver CWE-79
2.6
2009-10-05 CVE-2009-3561 Path Traversal vulnerability in Xerver 4.32
Directory traversal vulnerability in Xerver HTTP Server 4.32 allows remote attackers to read arbitrary files via a full pathname with a drive letter in the currentPath parameter in a chooseDirectory action.
network
low complexity
xerver CWE-22
5.0
2009-10-05 CVE-2009-3544 Information Exposure vulnerability in Xerver 4.32
Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HTML file name.
network
low complexity
xerver CWE-200
5.0
2005-12-31 CVE-2005-4774 Input Validation vulnerability in Xerver 4.17
Cross-site scripting (XSS) vulnerability in Xerver 4.17 allows remote attackers to inject arbitrary web script or HTML after a /%00/ sequence at the end of the URI.
network
xerver
4.3
2005-10-23 CVE-2005-3293 Input Validation vulnerability in Xerver 4.17H
Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2) list directory contents via a trailing null character.
network
low complexity
xerver
5.0
2002-07-26 CVE-2002-0448 Request Denial Of Service vulnerability in Xerver
Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many "C:/" sequences.
network
low complexity
xerver
5.0
2002-07-26 CVE-2002-0447 Directory Traversal vulnerability in Xerver
Directory traversal vulnerability in Xerver Free Web Server 2.10 and earlier allows remote attackers to list arbitrary directories via a ..
network
low complexity
xerver
5.0