Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown
CVE-2019-5447
Disclosure Date: July 15, 2019 (last updated November 27, 2024)
A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.
0
Attacker Value
Unknown
CVE-2014-7226
Disclosure Date: October 10, 2014 (last updated October 05, 2023)
The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file with certain invalid UTF-8 byte sequences that are interpreted as executable macro symbols.
0
Attacker Value
Unknown
CVE-2014-6287
Disclosure Date: October 07, 2014 (last updated November 25, 2024)
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.
0
Attacker Value
Unknown
CVE-2008-0405
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) files and (2) directories via a .. (dot dot) in an account name, when requesting the / URI; and (3) append arbitrary data to a file via a .. (dot dot) in an account name, when requesting a URI composed of a "/?%0a" sequence followed by the data.
0
Attacker Value
Unknown
CVE-2008-0406
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a denial of service (daemon crash) via a long account name.
0
Attacker Value
Unknown
CVE-2008-0408
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
HTTP File Server (HFS) before 2.2c allows remote attackers to append arbitrary text to the log file by using the base64 representation of this text during HTTP Basic Authentication.
0
Attacker Value
Unknown
CVE-2008-0409
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in HTTP File Server (HFS) before 2.2c allows remote attackers to inject arbitrary web script or HTML via the userinfo subcomponent of a URL.
0
Attacker Value
Unknown
CVE-2008-0407
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more difficult for an administrator to determine who made a remote request.
0
Attacker Value
Unknown
CVE-2008-0410
Disclosure Date: January 29, 2008 (last updated October 04, 2023)
HTTP File Server (HFS) before 2.2c allows remote attackers to obtain configuration and usage details by using an id element such as <id>%version%</id> in HTTP Basic Authentication instead of a username and password, as demonstrated by placing this id element in the userinfo subcomponent of a URL.
0