CVE-2014-7226
The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file with certain invalid UTF-8 byte sequences that are interpreted as executable macro symbols.
- Affected products
- Rejetto Http File Server
- Rejetto Http File Server
- ≤ 2.3c
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 9.2% (95th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2014-10-10
CVE-2014-7226 at NVD
4 known exploits for CVE-2014-7226
Proof-of-concept code and exploit modules indexed by Sploitus