This page lists publicly disclosed CVE vulnerabilities affecting jerod_moemeka xedus (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2004-1646 | Directory traversal vulnerability in Xedus 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | [email protected] | 5.0 | 5.11% | 2004-08-30 | 2026-04-16 |
| CVE-2004-1645 | Cross-site scripting (XSS) vulnerability in Xedus 1.0 allows remote attackers to execute arbitrary web script or HTML via the (1) username parameter to test.x, (2) username parameter to TestServer.x, or (3) param parameter to testgetrequest.x. | [email protected] | 4.3 | 0.89% | 2004-08-30 | 2026-04-16 |
| CVE-2004-1644 | Xedus 1.0 allows remote attackers to cause a denial of service (refuse connections) by connecting multiple times from the same IP address. | [email protected] | 5.0 | 1.07% | 2004-08-30 | 2026-04-16 |