Sploitus

CVE-2024-23692

20 known exploits for CVE-2024-23692

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.

Affected products
Rejetto Http File Server
Rejetto Http File Server
≀ 2.4
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
99.5% (100th percentile)
Weakness
CWE-1336, CWE-94
NVD status
Analyzed
Published
2024-05-31
Attack patterns
CAPEC-242
Entry point
n query param
Path
/?n=%0A&cmd=cmd+/c+powershell+-enc+<encoded>&search=%25xxx%25url%25:%password%}\{.exec|{.?cmd.}|timeout=15|out=abc.}\{.?n.}\{.?n.}RESULT:\{.?n.}\{.^abc.}====\{.?n.}
CVE-2024-23692 at NVD
Authoritative description, scoring and affected products

20 known exploits for CVE-2024-23692

Proof-of-concept code and exploit modules indexed by Sploitus

Exploit for Improper Neutralization of Special Elements Used in a Template Engine in Rejetto Http_File_Server
2026-08-08 sandimfzGITHUB
πŸ“„ Rejetto HTTP File Server 2.3m Unauthenticated Remote Code Execution
2026-02-18 indoushkaPACKETSTORMPHP
Rejetto HTTP File Server 2.3m - Remote Code Execution (RCE)
2025-03-28 VeryLazyTechEXPLOITDBPython
Exploit for Code Injection in Rejetto Http_File_Server
2025-03-06 999gawkboyyGITHUB
Exploit for Code Injection in Rejetto Http_File_Server
2024-12-21 NingXin2002GITHUB
Exploit for Code Injection in Rejetto Http_File_Server
2024-11-23 XiaomingXGITHUB
Exploit for Code Injection in Rejetto Http_File_Server
2024-09-15 verylazytechGITHUB
Exploit for Incorrect Authorization in Apache Ofbiz
2024-08-22 0x20cGITHUB
Exploit for Code Injection in Rejetto Http_File_Server
2024-07-10 pradeepbooGITHUB
Exploit for Code Injection in Rejetto Http_File_Server
2024-07-10 pradeepbooGITHUB
Exploit for Code Injection in Rejetto Http_File_Server
2024-06-18 0x20cGITHUB
Exploit for Code Injection in Rejetto Http_File_Server
2024-06-17 BBD-YZZGITHUB
Exploit for Code Injection in Rejetto Http_File_Server
2024-06-14 Mr-r00t11GITHUB
Rejetto HTTP File Server (HFS) Unauthenticated Remote Code Execution Exploit
2024-06-13 metasploitZDTRuby
Rejetto HTTP File Server (HFS) Unauthenticated Remote Code Execution
2024-06-13 sfewer-r7, Arseniy Sharoglazov, metasploit.comPACKETSTORMRuby
Exploit for Code Injection in Rejetto Http_File_Server
2024-06-13 jakabakosGITHUB
Exploit for Code Injection in Rejetto Http_File_Server
2024-06-13 vanboomqiGITHUB
Exploit for Code Injection in Rejetto Http_File_Server
2024-06-13 WanLiChangChengWanLiChangGITHUB
Exploit for Code Injection in Rejetto Http_File_Server
2024-06-11 k3lpi3b4nsh33GITHUB
Rejetto HTTP File Server (HFS) Unauthenticated Remote Code Execution
2024-05-25 sfewer-r7, Arseniy SharoglazovMETASPLOITRuby