Vulnerabilities > Rejetto

DATE CVE VULNERABILITY TITLE RISK
2024-07-04 CVE-2024-39943 OS Command Injection vulnerability in Rejetto Http File Server
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions).
network
low complexity
rejetto CWE-78
8.8
2024-05-31 CVE-2024-23692 Code Injection vulnerability in Rejetto Http File Server
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability.
network
low complexity
rejetto CWE-94
critical
9.8
2020-06-08 CVE-2020-13432 Classic Buffer Overflow vulnerability in Rejetto Http File Server 2.3M
rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access violation via concurrent HTTP requests with a long URI or long HTTP headers.
network
low complexity
rejetto CWE-120
5.0
2014-10-10 CVE-2014-7226 Code Injection vulnerability in Rejetto Http File Server
The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file with certain invalid UTF-8 byte sequences that are interpreted as executable macro symbols.
network
low complexity
rejetto CWE-94
7.5
2014-10-07 CVE-2014-6287 Code Injection vulnerability in Rejetto Http File Server 2.3/2.3A/2.3B
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.
network
low complexity
rejetto CWE-94
critical
10.0