VDB
CVE-2014-6287
CVE-2014-6287
PUBLISHED
KEV
CVSS 10 CRITICAL
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.
EPSS 94.36% · 100.0th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
94.36%
100.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| rejetto | http_file_server | 2.3 |
Timeline
- Sep 13, 2014 PoC Published
- Oct 7, 2014 CVE Published
- Oct 9, 2014 PoC Published
- Jan 4, 2016 PoC Published
- Jan 4, 2016 PoC Published
- May 29, 2018 PoC Published
- Jun 25, 2020 PoC Published
- Oct 9, 2020 PoC Published
- Oct 9, 2020 PoC Published
- Oct 9, 2020 PoC Published
- Oct 16, 2020 PoC Published
- Nov 30, 2020 PoC Published
References
- VU#251276 third-party-advisory
- 39161 exploit
- http://packetstormsecurity.com/files/128243/HttpFileServer-2.3.x-Remote-Command-Execution.html url
- https://github.com/rapid7/metasploit-framework/pull/3793 url
- http://packetstormsecurity.com/files/135122/Rejetto-HTTP-File-Server-2.3.x-Remote-Code-Execution.html url
- http://packetstormsecurity.com/files/160264/Rejetto-HttpFileServer-2.3.x-Remote-Command-Execution.html url
- http://packetstormsecurity.com/files/161503/HFS-HTTP-File-Server-2.3.x-Remote-Code-Execution.html url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-6287 url
- https://nvd.nist.gov/vuln/detail/CVE-2014-6287 advisory
- https://www.exploit-db.com/exploits/39161 url