vendor:
HttpFileServer
by:
Óscar Andreu
9.8
CVSS
CRITICAL
Remote Command Execution
78
CWE
Product Name: HttpFileServer
Affected Version From: 2.3.x
Affected Version To: 2.3.x
Patch Exists: YES
Related CWE: CVE-2014-6287
CPE: 2.3.x
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows Server 2008, Windows 8, Windows 7
2020
Rejetto HttpFileServer 2.3.x – Remote Command Execution (3)
Rejetto HttpFileServer 2.3.x is vulnerable to Remote Command Execution. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable server. This request contains a malicious payload which is then executed on the server. This vulnerability was discovered by Óscar Andreu and is tracked as CVE-2014-6287.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of the software.