CVE-2005-3293

Xerver 4.17 - Directory Traversal and Information Disclosure via Trailing Dot and Null Character

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2005-3293. PoCs published by Ziv Kamir.

AI-analyzed exploit summary The provided text describes multiple input validation vulnerabilities in Xerver, including directory listing disclosure, script content disclosure, and cross-site scripting (XSS). It provides example URLs demonstrating the vulnerabilities but does not include executable exploit code.

Description

Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2) list directory contents via a trailing null character.

Exploits (2)

exploitdb WRITEUP VERIFIED
by Ziv Kamir · textremotewindows
https://www.exploit-db.com/exploits/26374

The provided text describes multiple input validation vulnerabilities in Xerver, including directory listing disclosure, script content disclosure, and cross-site scripting (XSS). It provides example URLs demonstrating the vulnerabilities but does not include executable exploit code.

Classification
Writeup 90%
Attack Type
Info Leak | Xss
Complexity
Trivial
Reliability
Theoretical
Target: Xerver (version not specified)
No auth needed
Prerequisites: Access to the target web server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Ziv Kamir · textremotewindows
https://www.exploit-db.com/exploits/26375

The provided text describes multiple input validation vulnerabilities in Xerver, including directory traversal, information disclosure, and XSS. It does not contain executable exploit code but references the vulnerability details and an example URL.

Classification
Writeup 90%
Attack Type
Info Leak | Xss
Complexity
Trivial
Reliability
Theoretical
Target: Xerver (version not specified)
No auth needed
Prerequisites: Network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/20076
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/22785
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/20075
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15135
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015079
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/22786
Exploit, Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17243

Scores

EPSS 0.0349
EPSS Percentile 87.6%

Details

Status published
Products (1)
xerver/xerver 4.17h
Published Oct 23, 2005
Tracked Since Feb 18, 2026