S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 7, 2024

CVE-2014-6287 Scanner

CVE-2014-6287 scanner - Remote Code Execution (RCE) vulnerability in Rejetto HTTP File Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2014-6287
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Rejetto HTTP File Server (HFS) is a popular web server designed to share files over the internet. The server is specifically designed for personal use, allowing files to be shared between individuals or small groups without the need for complex network configurations. HFS is meant to provide a simple and easy-to-use platform for sharing files online. The product has been widely used worldwide due to its simplicity and ease of use.

CVE-2014-6287 is a critical vulnerability that was detected in Rejetto HTTP File Server. The vulnerability is located in the findMacroMarker function in the parserLib.pas file, which is a component of the server. The vulnerability allows an attacker to execute arbitrary programs remotely using a %00 sequence in a search action. Attackers can use this vulnerability to gain unauthorized access to the server and execute malicious code.

If CVE-2014-6287 is exploited, it can lead to severe consequences for HFS users. Attackers can use this vulnerability to steal sensitive information, disrupt the server's functionality, and install malware or ransomware. The vulnerability can also allow attackers to gain complete control over the server and use it as a launchpad for further attacks. In short, the vulnerability can put users' data and privacy at risk.

At s4e.io, our mission is to help individuals and organizations protect their digital assets from cyber threats. By subscribing to our pro features, readers can stay updated on the latest security vulnerabilities and receive personalized recommendations on how to protect their assets. Our platform offers a range of tools and resources to help users stay protected, including vulnerability scanning, penetration testing, and threat intelligence. With s4e.io, you can stay one step ahead of cyber threats and protect your digital assets with confidence.

 

REFERENCES

Solution Advice

Several precautions can be taken to protect against CVE-2014-6287, including the following:

  • Update HFS to the latest version available
  • Configure HFS to use a strong password for remote access
  • Use a firewall to block any suspicious incoming traffic
  • Use an antivirus solution with up-to-date virus definitions
  • Avoid clicking on links or downloading files from untrusted sources

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2014-6287 scanner - Remote Code Execution (RCE) vulnerability in Rejetto HTTP File Server | S4E