CVE-2008-0410

HFS HTTP File Server < 2.2b - Authentication Bypass

Title source: rule

Description

HTTP File Server (HFS) before 2.2c allows remote attackers to obtain configuration and usage details by using an id element such as <id>%version%</id> in HTTP Basic Authentication instead of a username and password, as demonstrated by placing this id element in the userinfo subcomponent of a URL.

Scores

EPSS 0.0059
EPSS Percentile 69.0%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

hfs/http_file_server < 2.2b

Timeline

Published Jan 29, 2008
Tracked Since Feb 18, 2026