vendor:
HttpFileServer
by:
Daniele Linguaglossa, Muhamad Fadzil Ramli
9,8
CVSS
CRITICAL
Remote Command Execution
78
CWE
Product Name: HttpFileServer
Affected Version From: 2.3b
Affected Version To: 2.3b
Patch Exists: NO
Related CWE: CVE-2014-6287
CPE: a:rejetto:http_file_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3, Windows 7 SP1 and Windows 8
2014
Rejetto HttpFileServer Remote Command Execution
Rejetto HttpFileServer (HFS) is vulnerable to remote command execution attack due to a poor regex in the file ParserLib.pas. This module exploit the HFS scripting commands by using '%00' to bypass the filtering. This module has been tested successfully on HFS 2.3b over Windows XP SP3, Windows 7 SP1 and Windows 8.
Mitigation:
No known mitigation or remediation for this vulnerability