CVE-2009-3544
Xerver HTTP Server 4.32 - Exposure of Sensitive Information via ::$DATA Suffix
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3544. PoCs published by Dr_IDE.
AI-analyzed exploit summary This is a writeup detailing a remote arbitrary source code disclosure vulnerability in Xerver HTTP Server v4.32. The vulnerability is exploited by appending '::$DATA' to the file path in the URL, which reveals the source code of the requested file.
Description
Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HTML file name.
Exploits (1)
This is a writeup detailing a remote arbitrary source code disclosure vulnerability in Xerver HTTP Server v4.32. The vulnerability is exploited by appending '::$DATA' to the file path in the URL, which reveals the source code of the requested file.