CVE-2014-6287
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.
- Affected products
- Rejetto Http File Server
- Rejetto Http File Server
- < 2.3c
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 99.3% (100th percentile)
- Weakness
- CWE-94
- NVD status
- Analyzed
- Published
- 2014-10-07
CVE-2014-6287 at NVD
22 known exploits for CVE-2014-6287
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Code Injection in Rejetto Http_File_Server
Exploit for Code Injection in Rejetto Http_File_Server
Exploit for Code Injection in Rejetto Http_File_Server
Exploit for Code Injection in Rejetto Http_File_Server
HFS Http File Server 2.3.x - Remote Command Execution Exploit (3)
HFS (HTTP File Server) 2.3.x - Remote Command Execution (3)
HFS (HTTP File Server) 2.3.x Remote Code Execution
Rejetto HttpFileServer 2.3.x - Remote Command Execution (3)
Rejetto HttpFileServer 2.3.x Remote Command Execution
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (2)
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (2)
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (2)
Rejetto HTTP File Server 2.3.x Remote Code Execution
Rejetto HttpFileServer Remote Command Execution
Rejetto HttpFileServer Remote Command Execution Exploit
Rejetto HTTP File Server (HFS) - Remote Command Execution (Metasploit)
Rejetto HttpFileServer Remote Command Execution
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (1)
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (1)
HttpFileServer 2.3.x Remote Command Execution Vulnerability
HttpFileServer 2.3.x Remote Command Execution
Rejetto HttpFileServer Remote Command Execution