CVE-2014-7226: Code Injection
Published Oct 10, 2014
·Updated
The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file with certain invalid UTF-8 byte sequences that are interpreted as executable macro symbols.
Affected Software
1 affected component
Rejetto HTTP File Server<=2.3c
Event History
Oct 10, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7226?
CVE-2014-7226 has a critical severity level due to its potential for remote code execution.
2
How do I fix CVE-2014-7226?
To fix CVE-2014-7226, upgrade to HFS version 2.3d or later, which mitigates the vulnerability.
3
What kind of attacks are possible with CVE-2014-7226?
CVE-2014-7226 allows attackers to execute arbitrary code on the server through crafted file uploads.
4
Which versions of HFS are affected by CVE-2014-7226?
CVE-2014-7226 affects all versions of Rejetto HTTP File Server up to and including 2.3c.
5
Is CVE-2014-7226 a known exploit?
Yes, CVE-2014-7226 is a widely recognized vulnerability that has been exploited in the wild.