Junglewise Threat Intelligence

CVE-2014-6287: Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability

CVE-2014-6287 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Vendors: Rejetto.

Executive brief

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS) allows remote attackers to execute arbitrary programs via a %00 sequence in a search action. This vulnerability is caused by improper control of generation of code (code injection).

Affected products

  • Rejetto HTTP File Server (HFS) 2.3x before 2.3c

Timeline

  • 2014-09-11: disclosed: Initial vulnerability disclosure and exploit availability via Packet Storm.
  • 2022-03-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.