Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Low
CVE-2024-23692
Disclosure Date: May 31, 2024 (last updated July 11, 2024)
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.
1
Attacker Value
Unknown
CVE-2024-39943
Disclosure Date: July 04, 2024 (last updated July 09, 2024)
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js).
0
Attacker Value
Unknown
CVE-2024-1227
Disclosure Date: March 12, 2024 (last updated April 01, 2024)
An open redirect vulnerability, the exploitation of which could allow an attacker to create a custom URL and redirect a legitimate page to a malicious site.
0
Attacker Value
Unknown
CVE-2024-1226
Disclosure Date: March 12, 2024 (last updated April 01, 2024)
The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing HTTP headers. The inclusion of invalidated data in an HTTP header allows an attacker to specify the full HTTP response represented by the browser. An attacker could control the response and craft attacks such as cross-site scripting and cache poisoning attacks.
0
Attacker Value
Unknown
CVE-2020-13432
Disclosure Date: June 08, 2020 (last updated February 21, 2025)
rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access violation via concurrent HTTP requests with a long URI or long HTTP headers.
0
Attacker Value
Unknown
CVE-2014-7226
Disclosure Date: October 10, 2014 (last updated October 05, 2023)
The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file with certain invalid UTF-8 byte sequences that are interpreted as executable macro symbols.
0
Attacker Value
Unknown
CVE-2014-6287
Disclosure Date: October 07, 2014 (last updated November 25, 2024)
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.
0