Myserver is a narrowly scoped vendor with a single core product that occupies a more prominent position in the vulnerability landscape than its modest disclosure volume might suggest. The exposure centers on path-traversal and directory-restriction weaknesses characteristic of file-serving and access-control logic, and the vendor's disclosures frequently acquire public exploit code. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Myserver over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-2516MEDIUM Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET command with a large number of "./" sequences followed by ". | Dec 31, 2004 | 5.0 | 25 | NO | YES |
CVE-2008-5160MEDIUM Unspecified vulnerability in MyServer 0.8.11 allows remote attackers to cause a denial of service (daemon crash) via multiple invalid requests with the HTTP GET, DELETE, OPTIONS, a | Nov 18, 2008 | 5.0 | 23 | NO | YES |
CVE-2004-2517MEDIUM myServer 0.7.1 allows remote attackers to cause a denial of service (crash) via a long HTTP POST request in a View=Logon operation to index.html. | Dec 31, 2004 | 5.0 | 23 | NO | YES |
CVE-2007-3364MEDIUM Cross-site scripting (XSS) vulnerability in the cgi-bin/post.mscgi sample page in MyServer 0.8.9 allows remote attackers to inject arbitrary web script or HTML via the body content | Jun 22, 2007 | 4.3 | 22 | NO | YES |
CVE-2007-2414HIGH MyServer before 0.8.8 allows remote attackers to cause a denial of service via unspecified vectors. | May 1, 2007 | 7.8 | 21 | NO | NO |
CVE-2007-1588HIGH server.cpp in MyServer 0.8.5 calls Process::setuid before calling Process::setgid and thus does not properly drop privileges, which might allow remote attackers to execute CGI prog | Mar 21, 2007 | 7.5 | 19 | NO | NO |
CVE-2002-2240MEDIUM Directory traversal vulnerability in MyServer 0.11 and 0.2 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP GET request. | Dec 31, 2002 | 5.0 | 19 | NO | NO |
CVE-2005-1658MEDIUM Directory traversal vulnerability in filemanager.cpp in MyServer 0.8 allows remote attackers to list the parent directory of the web root via a URL with a "..." (triple dot). | May 18, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-1659MEDIUM Cross-site scripting (XSS) vulnerability in filemanager.cpp in MyServer 0.8 allows remote attackers to inject arbitrary Javascript via a URL with a "..." (triple dot) followed by | May 18, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Myserver.
Media articles that mention a CVE ID that affects a product developed by Myserver — matched by CVE ID, not by vendor name.