Sploitus

CVE-2014-6287

22 known exploits for CVE-2014-6287

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.

Affected products
Rejetto Http File Server
Rejetto Http File Server
< 2.3c
Fix
Available
CVSS 2.0
10.0 HIGH
CVSS 3.1
9.8 CRITICAL
EPSS
99.3% (100th percentile)
Weakness
CWE-94
NVD status
Analyzed
Published
2014-10-07
CVE-2014-6287 at NVD
Authoritative description, scoring and affected products

22 known exploits for CVE-2014-6287

Proof-of-concept code and exploit modules indexed by Sploitus

Exploit for Code Injection in Rejetto Http_File_Server
2026-05-16 abanop22333GITHUB
Exploit for Code Injection in Rejetto Http_File_Server
2026-03-10 R3fr4ktGITHUB
Exploit for Code Injection in Rejetto Http_File_Server
2026-01-25 jagg3rsecGITHUB
Exploit for Code Injection in Rejetto Http_File_Server
2025-09-16 nika0x38GITHUB
HFS Http File Server 2.3.x - Remote Command Execution Exploit (3)
2021-02-23 PergyzZDTPython
HFS (HTTP File Server) 2.3.x - Remote Command Execution (3)
2021-02-23 PergyzEXPLOITDBPython
HFS (HTTP File Server) 2.3.x Remote Code Execution
2021-02-23 PergyzPACKETSTORMPython
Rejetto HttpFileServer 2.3.x - Remote Command Execution (3)
2020-11-30 Óscar AndreuEXPLOITDBPython
Rejetto HttpFileServer 2.3.x Remote Command Execution
2020-11-29 Oscar AndreuPACKETSTORMPython
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (2)
2016-01-04 Avinash ThapaZDTPython
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (2)
2016-01-04 Avinash ThapaEXPLOITPACKPython
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (2)
2016-01-04 Avinash ThapaEXPLOITDBPython
Rejetto HTTP File Server 2.3.x Remote Code Execution
2016-01-04 Avinash Kumar ThapaPACKETSTORMPython
Rejetto HttpFileServer Remote Command Execution
2014-10-10 RootSEEBUGRuby
Rejetto HttpFileServer Remote Command Execution Exploit
2014-10-09 metasploitZDTRuby
Rejetto HTTP File Server (HFS) - Remote Command Execution (Metasploit)
2014-10-09 MetasploitEXPLOITDBRuby
Rejetto HttpFileServer Remote Command Execution
2014-10-08 Muhamad Fadzil RamliPACKETSTORMRuby
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (1)
2014-09-15 Daniele LinguaglossaEXPLOITPACK
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (1)
2014-09-15 Daniele LinguaglossaEXPLOITDB
HttpFileServer 2.3.x Remote Command Execution Vulnerability
2014-09-13 Daniele LinguaglossaZDT
HttpFileServer 2.3.x Remote Command Execution
2014-09-12 Daniele LinguaglossaPACKETSTORM
Rejetto HttpFileServer Remote Command Execution
2014-09-11 Daniele Linguaglossa <danielelinguaglossa@gmail.com>, Muhamad Fadzil Ramli <mind1355@gmail.com>METASPLOITRuby