HTTP File Server before 2.3c is susceptible to remote command execution. The findMacroMarker function in parserLib.pas allows an attacker to execute arbitrary programs via a %00 sequence in a search action. Therefore, an attacker can obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
id: 'CVE-2014-6287'
info:
name: HTTP File Server <2.3c - Remote Command Execution
author: j4vao
...