CVE-2005-3293
Xerver 4.17 - Directory Traversal and Information Disclosure via Trailing Dot and Null Character
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2005-3293. PoCs published by Ziv Kamir.
AI-analyzed exploit summary The provided text describes multiple input validation vulnerabilities in Xerver, including directory listing disclosure, script content disclosure, and cross-site scripting (XSS). It provides example URLs demonstrating the vulnerabilities but does not include executable exploit code.
Description
Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2) list directory contents via a trailing null character.
Exploits (2)
The provided text describes multiple input validation vulnerabilities in Xerver, including directory listing disclosure, script content disclosure, and cross-site scripting (XSS). It provides example URLs demonstrating the vulnerabilities but does not include executable exploit code.
The provided text describes multiple input validation vulnerabilities in Xerver, including directory traversal, information disclosure, and XSS. It does not contain executable exploit code but references the vulnerability details and an example URL.