PT-2009-5835 · Xerver · Xerver Http Server

Dr_Ide

·

Published

2009-10-05

·

Updated

2017-09-19

·

CVE-2009-3544

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xerver HTTP Server version 4.32
Description The issue allows remote attackers to obtain the source code for a web page via a specially crafted HTTP request. This is achieved by adding ::$DATA after the HTML file name in the request.
Recommendations For Xerver HTTP Server version 4.32, consider restricting access to sensitive web pages until a fix is available. As a temporary workaround, avoid using the ::$DATA suffix in HTTP requests to minimize the risk of source code exposure.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3544

Affected Products

Xerver Http Server