CVE-2014-6287: Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.
Other sources
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6287?
CVE-2014-6287 is classified as a critical vulnerability due to its potential for remote command execution.
How do I fix CVE-2014-6287?
To fix CVE-2014-6287, upgrade Rejetto HTTP File Server to version 2.3c or later.
Who is affected by CVE-2014-6287?
CVE-2014-6287 affects users of Rejetto HTTP File Server versions 2.3x prior to 2.3c.
What type of vulnerability is CVE-2014-6287?
CVE-2014-6287 is a remote command execution vulnerability.
Can CVE-2014-6287 be exploited without authentication?
Yes, CVE-2014-6287 can be exploited by unauthenticated remote attackers.