CVE-2014-6287: Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 99.3% chance of exploitation in the next 30 days.
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.
Affected products
- Rejetto HTTP File Server: from 2.3, before 2.3c (fixed in 2.3c)
Published 2014-10-07. Last modified 2026-06-17.