Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2022-25847

Disclosure Date: January 26, 2023 (last updated November 08, 2023)
All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its contents with links that include the actual file names without any sanitization or output encoding.
Attacker Value
Unknown

CVE-2022-21192

Disclosure Date: January 26, 2023 (last updated November 08, 2023)
All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other checks and protections employed to the req.url passed as-is to path.join().
Attacker Value
Unknown

CVE-2003-1144

Disclosure Date: November 04, 2003 (last updated February 22, 2025)
Buffer overflow in the log viewing interface in Perception LiteServe 1.25 through 2.2 allows remote attackers to execute arbitrary code via a GET request with a long file name.
0
Attacker Value
Unknown

CVE-2002-2192

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web script via (1) a Host: header when DNS wildcards are supported or (2) the query string in a "dir" request to indexed folders.
0
Attacker Value
Unknown

CVE-2002-2406

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Buffer overflow in HTTP server in LiteServe 2.0, 2.0.1 and 2.0.2 allows remote attackers to cause a denial of service (hang) via a large number of percent characters (%) in an HTTP GET request.
0
Attacker Value
Unknown

CVE-2002-1986

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Perception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP request with a trailing dot (".").
0
Attacker Value
Unknown

CVE-2002-2369

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Perception LiteServe 2.0 allows remote attackers to read password protected files via a leading "/./" in a URL.
0
Attacker Value
Unknown

CVE-2001-0795

Disclosure Date: October 18, 2001 (last updated February 22, 2025)
Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3 file names.