Xerver is a niche web-server product whose vulnerability footprint concentrates on application-layer input-handling and information-disclosure weaknesses, including cross-site scripting, path traversal, and exposure of sensitive data. While the vendor's disclosure volume is modest, its vulnerabilities have frequently acquired public exploit code, reflecting the web-application attack surface the product presents. Current counts for severity, exploitation activity, and exposure are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xerver over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0448MEDIUM Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many "C:/" sequences. | Jul 26, 2002 | 5.0 | 35 | NO | YES |
CVE-2009-3561MEDIUM Directory traversal vulnerability in Xerver HTTP Server 4.32 allows remote attackers to read arbitrary files via a full pathname with a drive letter in the currentPath parameter in | Oct 5, 2009 | 5.0 | 24 | NO | YES |
CVE-2009-3544MEDIUM Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HTML file name. | Oct 5, 2009 | 5.0 | 24 | NO | YES |
CVE-2005-3293MEDIUM Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2) list directory contents via a trailing null character. | Oct 23, 2005 | 5.0 | 23 | NO | YES |
CVE-2005-4774MEDIUM Cross-site scripting (XSS) vulnerability in Xerver 4.17 allows remote attackers to inject arbitrary web script or HTML after a /%00/ sequence at the end of the URI. | Dec 31, 2005 | 4.3 | 21 | NO | YES |
Cross-site scripting (XSS) vulnerability in Xerver HTTP Server 4.32 allows remote attackers to inject arbitrary web script or HTML via the currentPath parameter in a chooseDirector | Oct 5, 2009 | 2.6 | 20 | NO | YES |
CVE-2002-0447MEDIUM Directory traversal vulnerability in Xerver Free Web Server 2.10 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in an HTTP GET request. | Jul 26, 2002 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xerver.
Media articles that mention a CVE ID that affects a product developed by Xerver — matched by CVE ID, not by vendor name.