Raidenhttpd is a lightweight HTTP server whose vulnerability profile, while modestly represented in the landscape, reflects its role as a web-facing component with a recurring exposure to input-handling issues. The vendor's disclosures cluster around cross-site scripting and related web-layer weaknesses, and public exploit code has an elevated tendency to emerge for identified flaws in this server. Defenders deploying this software should prioritize tracking security advisories and restricting network exposure; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Raidenhttpd over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4723MEDIUM PHP remote file inclusion vulnerability in raidenhttpd-admin/slice/check.php in RaidenHTTPD 1.1.49, when register_globals and WebAdmin is enabled, allows remote attackers to execut | Sep 12, 2006 | 5.1 | 23 | NO | YES |
CVE-2005-0623HIGH Buffer overflow in RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to execute arbitrary code via a long URL. | Mar 1, 2005 | 7.5 | 22 | NO | NO |
CVE-2005-0622MEDIUM RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to view the PHP source code via an HTTP GET request for a filename with a trailing (1) . (dot | Mar 1, 2005 | 5.0 | 17 | NO | NO |
CVE-2006-0949MEDIUM RaidenHTTPD 1.1.47 allows remote attackers to obtain source code of script files, including PHP, via crafted requests involving (1) "." (dot), (2) space, and (3) "/" (slash) charac | Mar 6, 2006 | 5.0 | 15 | NO | NO |
CVE-2008-0622MEDIUM Cross-site scripting (XSS) vulnerability in RaidenHTTPD 2.0.19 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the ula | Feb 6, 2008 | 4.3 | 14 | NO | NO |
CVE-2007-3343MEDIUM Cross-site scripting (XSS) vulnerability in RaidenHTTPD before 2.0.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Jun 22, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Raidenhttpd.
Media articles that mention a CVE ID that affects a product developed by Raidenhttpd — matched by CVE ID, not by vendor name.