HTTP File Server是一款专为个人用户所设计的HTTP文件服务器,它提供虚拟档案系统,支持新增、移除虚拟档案资料夹等。 Rejetto HTTP File Server 2.3c及之前版本中的parserLib.pas文件中的‘findMacroMarker’函数中存在安全漏洞,该漏洞源于parserLib.pas文件没有正确处理空字节。远程攻击者可借助搜索操作中的‘%00’序列利用该漏洞执行任意程序。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | HttpFileServer httpd 2.3 | https://github.com/roughiz/cve-2014-6287.py | POC详情 |
| 2 | None | https://github.com/Nicoslo/Windows-exploitation-Rejetto-HTTP-File-Server-HFS-2.3.x-CVE-2014-6287 | POC详情 |
| 3 | A write up on the Steel Mountain box from TryHackMe.com and exploit for CVE-2014-6287 | https://github.com/wizardy0ga/THM-Steel_Mountain-CVE-2014-6287 | POC详情 |
| 4 | a python3 version of the exploit written for CVE-2014-6287. Useful for completing the "Steel Mountain" room on TryHackMe.com without the use of metasploit. | https://github.com/mrintern/thm_steelmountain_CVE-2014-6287 | POC详情 |
| 5 | CVE-2014-6287 Rejetto HFS 2.3 | https://github.com/hadrian3689/rejetto_hfs_rce | POC详情 |
| 6 | CVE-2014-6287 | https://github.com/randallbanner/Rejetto-HTTP-File-Server-HFS-2.3.x---Remote-Command-Execution | POC详情 |
| 7 | Rejetto http File Server 2.3.x (Reverse shell) | https://github.com/0xTabun/CVE-2014-6287 | POC详情 |
| 8 | Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c | https://github.com/zhsh9/CVE-2014-6287 | POC详情 |
| 9 | None | https://github.com/francescobrina/hfs-cve-2014-6287-exploit | POC详情 |
| 10 | Rejetto http File Server 2.3.x (Reverse shell) | https://github.com/10cks/CVE-2014-6287 | POC详情 |
| 11 | HTTP File Server before 2.3c is susceptible to remote command execution. The findMacroMarker function in parserLib.pas allows an attacker to execute arbitrary programs via a %00 sequence in a search action. Therefore, an attacker can obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2014/CVE-2014-6287.yaml | POC详情 |
| 12 | Rejetto HttpFileServer 2.3.x - Remote Command Execution (RevShell) | https://github.com/Z3R0-0x30/CVE-2014-6287 | POC详情 |
| 13 | This repository contains Detailed explanation and working poc for Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution. | https://github.com/rahisec/rejetto-http-file-server-2.3.x-RCE-exploit-CVE-2014-6287 | POC详情 |
| 14 | A Rust implementation of the CVE-2014-6287 exploit targeting Rejetto HTTP File Server (HFS) versions 2.3x before 2.3c. | https://github.com/nika0x38/CVE-2014-6287 | POC详情 |
| 15 | Remote Command Execution exploit for Rejetto HTTP File Server 2.3.x (CVE-2014-6287) rewritten in Python 3 for modern offensive security testing. | https://github.com/JoaZ94/rejjeto_hfs-rce-exploit-cve-2014-6287 | POC详情 |
| 16 | None | https://github.com/jagg3rsec/CVE-2014-6287 | POC详情 |
| 17 | Rejetto HttpFileServer 2.3.x - Remote Command Execution (RevShell) | https://github.com/Z3R0space/CVE-2014-6287 | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2014-7204 | Exuberant Ctags 资源管理错误漏洞 | |
| CVE-2014-4871 | NetCommWireless NB604N Routers 跨站脚本漏洞 | |
| CVE-2014-4870 | Brocade Vyatta 5400 vRouter 输入验证漏洞 | |
| CVE-2014-4869 | Brocade Vyatta 5400 vRouter 权限许可和访问控制漏洞 | |
| CVE-2014-4868 | Brocade Vyatta 5400 vRouter 操作系统命令注入漏洞 | |
| CVE-2014-4802 | IBM Business Process Manager 权限许可和访问控制漏洞 | |
| CVE-2014-3399 | Cisco Adaptive Security Appliances 代码注入漏洞 | |
| CVE-2014-0940 | IBM Tivoli Service Automation Manager 跨站脚本漏洞 | |
| CVE-2014-7295 | MediaWiki 跨站脚本漏洞 | |
| CVE-2014-7235 | FreePBX 代码注入漏洞 | |
| CVE-2014-3565 | Net-SNMP 资源管理错误漏洞 | |
| CVE-2014-7189 | Google Go 权限许可和访问控制漏洞 | |
| CVE-2014-6603 | Suricata 资源管理错误漏洞 | |
| CVE-2014-6434 | GoPro HERO 3+ 操作系统命令注入漏洞 | |
| CVE-2014-6433 | GoPro HERO 3+ 代码注入漏洞 | |
| CVE-2014-5503 | Sophos Cyberoam appliances with CyberoamOS SQL注入漏洞 | |
| CVE-2014-5502 | Sophos Cyberoam appliances with CyberoamOS 操作系统命令注入漏洞 | |
| CVE-2014-5501 | Sophos Cyberoam appliances with CyberoamOS 基于栈的缓冲区溢出漏洞 | |
| CVE-2014-3632 | 多款Red Hat产品权限许可和访问控制问题漏洞 |
暂无评论