CVE-2024-39943
- EPSS 78.34%
- Veröffentlicht 04.07.2024 23:15:09
- Zuletzt bearbeitet 21.11.2024 09:28:37
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead ...
CVE-2024-23692
- EPSS 94.3%
- Veröffentlicht 31.05.2024 10:15:09
- Zuletzt bearbeitet 31.10.2025 21:57:05
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially ...
CVE-2024-1226
- EPSS 0.12%
- Veröffentlicht 12.03.2024 15:15:47
- Zuletzt bearbeitet 21.11.2024 08:50:05
The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing HTTP headers. The inclusion of invalidated data in an HTTP header allows an attacker to specify the full HTTP response represented ...
CVE-2024-1227
- EPSS 0.04%
- Veröffentlicht 12.03.2024 15:15:47
- Zuletzt bearbeitet 21.11.2024 08:50:06
An open redirect vulnerability, the exploitation of which could allow an attacker to create a custom URL and redirect a legitimate page to a malicious site.
CVE-2020-13432
- EPSS 7.35%
- Veröffentlicht 08.06.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:01:15
rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access violation via concurrent HTTP requests with a long URI or long HTTP headers.
CVE-2014-7226
- EPSS 8.06%
- Veröffentlicht 10.10.2014 01:55:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file with certain invalid UTF-8 byte sequences that are interpreted as executable macro symbols.
- EPSS 94.36%
- Veröffentlicht 07.10.2014 10:55:04
- Zuletzt bearbeitet 22.10.2025 01:16:03
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.