CVE-2014-6287
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 99% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-94
מוצרים מושפעים
rejetto: http file server
קישורים
- http://packetstormsecurity.com/files/128243/HttpFileServer-2.3.x-Remote-Comman… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/135122/Rejetto-HTTP-File-Server-2.3.x-Rem… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/160264/Rejetto-HttpFileServer-2.3.x-Remot… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/161503/HFS-HTTP-File-Server-2.3.x-Remote-… ExploitThird Party AdvisoryVDB Entry
- https://github.com/rapid7/metasploit-framework/pull/3793 Exploit
- https://www.exploit-db.com/exploits/39161/ ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/128243/HttpFileServer-2.3.x-Remote-Comman… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/135122/Rejetto-HTTP-File-Server-2.3.x-Rem… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/160264/Rejetto-HttpFileServer-2.3.x-Remot… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/161503/HFS-HTTP-File-Server-2.3.x-Remote-… ExploitThird Party AdvisoryVDB Entry