CVE-2009-4531

httpdx <1.4.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Dr_IDE · textremotewindows
https://www.exploit-db.com/exploits/34846

References (6)

Core 6
Core References
Exploit, URL Repurposed x_refsource_misc
http://freetexthost.com/eiyfyt0km5
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/58857
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/53733
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37013

Scores

EPSS 0.0707
EPSS Percentile 91.5%

Details

CWE
CWE-200
Status published
Products (3)
jasper/httpdx 1.4
jasper/httpdx 1.4.3
jasper/httpdx < 1.4.4
Published Dec 31, 2009
Tracked Since Feb 18, 2026