CVE-2014-6287 is a critical remote code execution vulnerability affecting Rejetto HTTP File Server (HFS) versions 2.3x prior to 2.3c. Attackers can exploit a flaw in the findMacroMarker function by injecting a %00 sequence into a search action, allowing them to execute arbitrary programs on the affected server. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, listed in CISA's KEV catalog, and has numerous public exploits available, including Metasploit modules and Nuclei templates, indicating widespread community awareness and exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.3, < 2.3cCPE matchmatch criteria | cpe:2.3:a:rejetto:http_file_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.