Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2019-25087

Disclosure Date: December 27, 2022 (last updated February 24, 2025)
A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file src/ResourceHost.cpp of the component URI Handler. The manipulation of the argument uri leads to path traversal: '../filedir'. The attack may be initiated remotely. The name of the patch is 1a0de56e4dafff9c2f9c8f6b130a764f7a50df52. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216863.
Attacker Value
Unknown

CVE-2019-5480

Disclosure Date: September 03, 2019 (last updated November 27, 2024)
A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary folders.
0
Attacker Value
Unknown

CVE-2018-16478

Disclosure Date: December 04, 2018 (last updated November 27, 2024)
A Path Traversal in simplehttpserver versions <=0.2.1 allows to list any file in another folder of web root.
0
Attacker Value
Unknown

CVE-2018-3787

Disclosure Date: August 31, 2018 (last updated November 27, 2024)
Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server.
Attacker Value
Unknown

CVE-2018-16134

Disclosure Date: August 29, 2018 (last updated November 27, 2024)
Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI.
0
Attacker Value
Unknown

CVE-2018-16133

Disclosure Date: August 29, 2018 (last updated November 27, 2024)
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
0
Attacker Value
Unknown

CVE-2018-3716

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
Attacker Value
Unknown

CVE-2006-1774

Disclosure Date: April 13, 2006 (last updated October 04, 2023)
HP System Management Homepage (SMH) 2.1.3.132, when running on CompaqHTTPServer/9.9 on Windows, Linux, or Tru64 UNIX, and when "Trust by Certificates" is not enabled, allows remote attackers to bypass authentication via a crafted URL.
0
Attacker Value
Unknown

CVE-2005-2982

Disclosure Date: September 20, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in CompaqHTTPServer 2.1 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.
0
Attacker Value
Unknown

CVE-2004-2100

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
GeoHttpServer, when configured to authenticate users, allows remote attackers to bypass authentication and access unauthorized files via a URL that contains %0a%0a (encoded newlines).
0