HFS HTTP File Server Multiple Security Vulnerabilities

BID:27423

Info

HFS HTTP File Server Multiple Security Vulnerabilities

Bugtraq ID: 27423
Class: Unknown
CVE:
Remote: Yes
Local: No
Published: Jan 23 2008 12:00AM
Updated: Jul 05 2016 10:00PM
Credit: Felipe Aragon and Alec Storm of Syhunt Security Research Team are credited with the discovery of these vulnerabilities.
Vulnerable: HTTP File Server HTTP File Server 2.3(Beta Build #174)
HTTP File Server HTTP File Server 2.3 beta
HTTP File Server HTTP File Server 2.2b
HTTP File Server HTTP File Server 2.2a
HTTP File Server HTTP File Server 2.2
HTTP File Server HTTP File Server 1.5g
Not Vulnerable: HTTP File Server HTTP File Server 2.2c

Discussion

HFS HTTP File Server Multiple Security Vulnerabilities

HFS (HTTP File Server) is prone to multiple security vulnerabilities, including cross-site scripting issues, an information-disclosure issue, an arbitrary file-creation issue, a denial-of-service issue, a username-spoofing issue, and a logfile-forging issue.

A successful exploit could allow an attacker to deny service to legitimate users, create and execute arbitrary files in the context of the webserver process, falsify log information, or execute arbitrary script code in the browser of an unsuspecting user. Other attacks are also possible.

Exploit / POC

HFS HTTP File Server Multiple Security Vulnerabilities

Attackers can exploit these issues through a browser. For the cross-site scripting issues, an attacker must entice an unsuspecting user to visit a malicious URI.

The following exploit code is available:

Solution / Fix

HFS HTTP File Server Multiple Security Vulnerabilities

Solution:
The vendor has released HFS 2.2c to address these issues. Please see the references for more information.


HTTP File Server HTTP File Server 2.2b

HTTP File Server HTTP File Server 2.3 beta

HTTP File Server HTTP File Server 2.3(Beta Build #174)

HTTP File Server HTTP File Server 2.2a

HTTP File Server HTTP File Server 1.5g

HTTP File Server HTTP File Server 2.2

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report