xerver kayıtları
xerver üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
24İzleyin | CVE-2002-0448Kavram kanıtı | Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many xerver · xerver | Orta5,0 | — | %14,9 | 26 Tem 2002 |
22İzleyin | CVE-2005-3293Kavram kanıtı | Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2) list directory contexerver · xerver | Orta5,0 | — | %7,8 | 23 Eki 2005 |
21İzleyin | CVE-2009-3561Kavram kanıtı | Directory traversal vulnerability in Xerver HTTP Server 4.32 allows remote attackers to read arbitrary files via a full pathname with a drivxerver · xerver · CWE-22 | Orta5,0 | — | %2,8 | 5 Eki 2009 |
21İzleyin | CVE-2009-3544Kavram kanıtı | Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA afxerver · xerver · CWE-200 | Orta5,0 | — | %2,6 | 5 Eki 2009 |
21İzleyin | CVE-2002-0447İstismar yok | Directory traversal vulnerability in Xerver Free Web Server 2.10 and earlier allows remote attackers to list arbitrary directories via a ..xerver · xerver | Orta5,0 | — | %2,3 | 26 Tem 2002 |
18İzleyin | CVE-2005-4774Kavram kanıtı | Cross-site scripting (XSS) vulnerability in Xerver 4.17 allows remote attackers to inject arbitrary web script or HTML after a /%00/ sequencxerver · xerver | Orta4,3 | — | %1,8 | 31 Ara 2005 |
10İzleyin | CVE-2009-3562Kavram kanıtı | Cross-site scripting (XSS) vulnerability in Xerver HTTP Server 4.32 allows remote attackers to inject arbitrary web script or HTML via the cxerver · xerver · CWE-79 | Düşük2,6 | — | %1,5 | 5 Eki 2009 |
- CVE-2002-044824İzleyin
Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many
OrtaCVSS 5,0Kavram kanıtıEPSS %15xerver · xerver26 Tem 2002
- CVE-2005-329322İzleyin
Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2) list directory conte
OrtaCVSS 5,0Kavram kanıtıEPSS %8xerver · xerver23 Eki 2005
- CVE-2009-356121İzleyin
Directory traversal vulnerability in Xerver HTTP Server 4.32 allows remote attackers to read arbitrary files via a full pathname with a driv
OrtaCVSS 5,0Kavram kanıtıEPSS %3xerver · xerver5 Eki 2009
- CVE-2009-354421İzleyin
Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA af
OrtaCVSS 5,0Kavram kanıtıEPSS %3xerver · xerver5 Eki 2009
- CVE-2002-044721İzleyin
Directory traversal vulnerability in Xerver Free Web Server 2.10 and earlier allows remote attackers to list arbitrary directories via a ..
OrtaCVSS 5,0İstismar yokEPSS %2xerver · xerver26 Tem 2002
- CVE-2005-477418İzleyin
Cross-site scripting (XSS) vulnerability in Xerver 4.17 allows remote attackers to inject arbitrary web script or HTML after a /%00/ sequenc
OrtaCVSS 4,3Kavram kanıtıEPSS %2xerver · xerver31 Ara 2005
- CVE-2009-356210İzleyin
Cross-site scripting (XSS) vulnerability in Xerver HTTP Server 4.32 allows remote attackers to inject arbitrary web script or HTML via the c
DüşükCVSS 2,6Kavram kanıtıEPSS %1xerver · xerver5 Eki 2009