CVE-2009-4535

Mongoose < 2.8.0 - Unauthenticated Source Code Exposure via URI Trailing Slash

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2009-4535. PoCs published by Dr_IDE.

AI-analyzed exploit summary This is a writeup describing directory traversal vulnerabilities in Mongoose Web Server v2.8. It provides example URLs demonstrating the vulnerability but does not include executable exploit code.

Description

Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending a / (slash) character to the URI.

Exploits (2)

exploitdb WRITEUP VERIFIED
by Dr_IDE · textremotewindows
https://www.exploit-db.com/exploits/12309

This is a writeup describing directory traversal vulnerabilities in Mongoose Web Server v2.8. It provides example URLs demonstrating the vulnerability but does not include executable exploit code.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Mongoose Web Server v2.8
No auth needed
Prerequisites: Network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Dr_IDE · textwebappsphp
https://www.exploit-db.com/exploits/9897

This exploit demonstrates a remote source disclosure vulnerability in Mongoose Web Server <= 2.8.0. By appending a trailing slash to a file request, the server reveals the source code of the file instead of executing it.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Mongoose Web Server <= 2.8.0
No auth needed
Prerequisites: Network access to the Mongoose Web Server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36934
Exploit, URL Repurposed x_refsource_misc
http://freetexthost.com/0lcsrgt3vw

Scores

EPSS 0.0668
EPSS Percentile 93.0%

Details

CWE
CWE-200
Status published
Products (1)
valenok/mongoose < 2.8.0
Published Dec 31, 2009
Tracked Since Feb 18, 2026