xerver 漏洞与 CVE 列表(7)

产品(CPE): — CVE 数: 7

xerver 漏洞概览

汇总 xerver 相关全部产品的 CVE 与安全漏洞情报,包括 CVSS、EPSS、公开时间与漏洞情报数据。

常见弱点模式包括 路径处理缺陷与跨站脚本,在 生产负载与软件部署 使用场景中可能带来 文件覆盖与会话劫持 等风险。

相关漏洞数据主要来源于公开漏洞披露与安全公告,可用于评估历史漏洞暴露面与修复优先级。

漏洞分布趋势(近 24 个月)

显示 177 CVE 数
«« 第一页 « 上一页 第 1 / 1 页 下一页 »
CVE 摘要 来源 最高 CVSS EPSS % 公开时间 更新时间
CVE-2009-3562 Cross-site scripting (XSS) vulnerability in Xerver HTTP Server 4.32 allows remote attackers to inject arbitrary web script or HTML via the currentPath parameter in a chooseDirectory action. [email protected] 2.6 1.49% 2009-10-05 2026-04-23
CVE-2009-3561 Directory traversal vulnerability in Xerver HTTP Server 4.32 allows remote attackers to read arbitrary files via a full pathname with a drive letter in the currentPath parameter in a chooseDirectory action. [email protected] 5.0 2.80% 2009-10-05 2026-04-23
CVE-2009-3544 Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HTML file name. [email protected] 5.0 2.59% 2009-10-05 2026-04-23
CVE-2005-4774 Cross-site scripting (XSS) vulnerability in Xerver 4.17 allows remote attackers to inject arbitrary web script or HTML after a /%00/ sequence at the end of the URI. [email protected] 4.3 1.75% 2005-12-31 2026-04-16
CVE-2005-3293 Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2) list directory contents via a trailing null character. [email protected] 5.0 3.49% 2005-10-23 2026-04-16
CVE-2002-0448 Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many "C:/" sequences. [email protected] 5.0 14.91% 2002-07-26 2026-06-16
CVE-2002-0447 Directory traversal vulnerability in Xerver Free Web Server 2.10 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in an HTTP GET request. [email protected] 5.0 2.28% 2002-07-26 2026-06-16
«« 第一页 « 上一页 第 1 / 1 页 下一页 »
cvelogic Threat Intelligence