PT-2009-5835 · Xerver · Xerver Http Server
Dr_Ide
·
Published
2009-10-05
·
Updated
2017-09-19
·
CVE-2009-3544
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Xerver HTTP Server version 4.32
Description
The issue allows remote attackers to obtain the source code for a web page via a specially crafted HTTP request. This is achieved by adding ::$DATA after the HTML file name in the request.
Recommendations
For Xerver HTTP Server version 4.32, consider restricting access to sensitive web pages until a fix is available. As a temporary workaround, avoid using the ::$DATA suffix in HTTP requests to minimize the risk of source code exposure.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xerver Http Server