Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2008-0409

EPSS 0.54% · P68
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2008-0409

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Cross-site scripting (XSS) vulnerability in HTTP File Server (HFS) before 2.2c allows remote attackers to inject arbitrary web script or HTML via the userinfo subcomponent of a URL.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
HFS 跨站脚本攻击漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
HTTP File Server是一款专为个人用户所设计的HTTP文件服务器,它提供虚拟档案系统,支持新增、移除虚拟档案资料夹等。 HFS没有正确地过滤某些输入便将其返回给了用户可能存在跨站脚本攻击漏洞,这可能导致在受影响服务器的用户浏览器会话中执行任意HTML和脚本代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2008-0409

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-0409

登录查看更多情报信息。

Same Patch Batch · n/a · 2008-01-28 · 10 CVEs total

CVE-2007-4770International Components for Unicode libicu内存破坏漏洞
CVE-2007-4771International Components for Unicode libicu堆缓冲区溢出漏洞
CVE-2008-0008PulseAudio pa_drop_root函数本地权限提升漏洞
CVE-2008-0405HTTP File Server 多个目录遍历漏洞
CVE-2008-0406HFS HTTP File Server 拒绝服务漏洞
CVE-2008-0407HFS HTTP File Server 输入验证漏洞
CVE-2008-0408HFS HTTP File Server HTTP基本验证漏洞
CVE-2008-0410HFS HTTP File Server HTTP基本验证漏洞
CVE-2008-0466WEB_wiz text_editor 'RTE_file_browser.asp'目录遍历漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2008-0409

No comments yet


Leave a comment