28631Third-party advisory
http://secunia.com/advisories/28631 CVE-2008-0406
Rejetto HTTP File Server (HFS) 1.5/2.x - Multiple Vulnerabilities
Record summary
CVE-2008-0406 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a denial of service (daemon crash) via a long account name.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBRejetto HTTP File Server (HFS) 1.5/2.x - Multiple VulnerabilitiesExploitDB exploitby Felipe M. AragonNot analyzed1 file
References
93581Third-party advisory
http://securityreason.com/securityalert/3581 rejetto.com
http://www.rejetto.com/hfs?f=wn 20080123 Syhunt: HFS (HTTP File Server) Log Arbitrary File/Directory Manipulation and Denial-of-Service Vulnerabilitiesmailing list
http://www.securityfocus.com/archive/1/486873/100/0/threaded 27423vdb entry
http://www.securityfocus.com/bid/27423 syhunt.com
http://www.syhunt.com/advisories/hfs-1-log.txt syhunt.com
http://www.syhunt.com/advisories/hfshack.txt hfs-filename-dos(39875)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/39875 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-0406