xerver records
7 published records for vendor xerver.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
24Monitor | CVE-2002-0448Proof of concept | Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many xerver · xerver | Medium5.0 | — | 14.9% | Jul 26, 2002 |
22Monitor | CVE-2005-3293Proof of concept | Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2) list directory contexerver · xerver | Medium5.0 | — | 7.8% | Oct 23, 2005 |
21Monitor | CVE-2009-3561Proof of concept | Directory traversal vulnerability in Xerver HTTP Server 4.32 allows remote attackers to read arbitrary files via a full pathname with a drivxerver · xerver · CWE-22 | Medium5.0 | — | 2.8% | Oct 5, 2009 |
21Monitor | CVE-2009-3544Proof of concept | Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA afxerver · xerver · CWE-200 | Medium5.0 | — | 2.6% | Oct 5, 2009 |
21Monitor | CVE-2002-0447No exploit | Directory traversal vulnerability in Xerver Free Web Server 2.10 and earlier allows remote attackers to list arbitrary directories via a ..xerver · xerver | Medium5.0 | — | 2.3% | Jul 26, 2002 |
18Monitor | CVE-2005-4774Proof of concept | Cross-site scripting (XSS) vulnerability in Xerver 4.17 allows remote attackers to inject arbitrary web script or HTML after a /%00/ sequencxerver · xerver | Medium4.3 | — | 1.8% | Dec 31, 2005 |
10Monitor | CVE-2009-3562Proof of concept | Cross-site scripting (XSS) vulnerability in Xerver HTTP Server 4.32 allows remote attackers to inject arbitrary web script or HTML via the cxerver · xerver · CWE-79 | Low2.6 | — | 1.5% | Oct 5, 2009 |
- CVE-2002-044824Monitor
Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many
MediumCVSS 5.0Proof of conceptEPSS 15%xerver · xerverJul 26, 2002
- CVE-2005-329322Monitor
Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2) list directory conte
MediumCVSS 5.0Proof of conceptEPSS 8%xerver · xerverOct 23, 2005
- CVE-2009-356121Monitor
Directory traversal vulnerability in Xerver HTTP Server 4.32 allows remote attackers to read arbitrary files via a full pathname with a driv
MediumCVSS 5.0Proof of conceptEPSS 3%xerver · xerverOct 5, 2009
- CVE-2009-354421Monitor
Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA af
MediumCVSS 5.0Proof of conceptEPSS 3%xerver · xerverOct 5, 2009
- CVE-2002-044721Monitor
Directory traversal vulnerability in Xerver Free Web Server 2.10 and earlier allows remote attackers to list arbitrary directories via a ..
MediumCVSS 5.0No exploitEPSS 2%xerver · xerverJul 26, 2002
- CVE-2005-477418Monitor
Cross-site scripting (XSS) vulnerability in Xerver 4.17 allows remote attackers to inject arbitrary web script or HTML after a /%00/ sequenc
MediumCVSS 4.3Proof of conceptEPSS 2%xerver · xerverDec 31, 2005
- CVE-2009-356210Monitor
Cross-site scripting (XSS) vulnerability in Xerver HTTP Server 4.32 allows remote attackers to inject arbitrary web script or HTML via the c
LowCVSS 2.6Proof of conceptEPSS 1%xerver · xerverOct 5, 2009