CVE-2009-3544

Xerver - Information Disclosure

Title source: rule

Description

Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HTML file name.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Dr_IDE · textremotewindows
https://www.exploit-db.com/exploits/9649

Scores

EPSS 0.0384
EPSS Percentile 88.0%

Classification

CWE
CWE-200
Status draft

Affected Products (1)

xerver/xerver

Timeline

Published Oct 05, 2009
Tracked Since Feb 18, 2026