Executive brief
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS) allows remote attackers to execute arbitrary programs via a %00 sequence in a search action. This vulnerability is caused by improper control of generation of code (code injection).
Affected products
- Rejetto HTTP File Server (HFS) 2.3x before 2.3c
Timeline
- 2014-09-11: disclosed: Initial vulnerability disclosure and exploit availability via Packet Storm.
- 2022-03-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.