CVE-2014-6287
Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
13Exploited in Wild
YesDecision
Descriptions
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.
La función findMacroMarker en parserLib.pas en Rejetto HTTP File Server (también conocido como HFS o HttpFileServer) 2.3x anterior a 2.3c permite a atacantes remotos ejecutar programas arbitrarios a través de una secuencia %00 en una acción de búsqueda.
HttpFileServer version 2.3.x suffers from a remote command execution vulnerability due to a poorly formed regex.
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-09-09 CVE Reserved
- 2014-09-12 CVE Published
- 2014-09-15 First Exploit
- 2022-03-25 Exploited in Wild
- 2022-04-15 KEV Due Date
- 2024-08-06 CVE Updated
- 2024-08-19 EPSS Updated
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (16)
URL | Tag | Source |
---|---|---|
http://www.kb.cert.org/vuls/id/251276 | Third Party Advisory | |
https://seclists.org/bugtraq/2014/Sep/85 | ||
http://www.rejetto.com/wiki/index.php?title=HFS:_scripting_commands |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rejetto Search vendor "Rejetto" | Http File Server Search vendor "Rejetto" for product "Http File Server" | >= 2.3 < 2.3c Search vendor "Rejetto" for product "Http File Server" and version " >= 2.3 < 2.3c" | - |
Affected
|