Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before...
Vulnerability Description
Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) files and (2) directories via a .. (dot dot) in an account name, when requesting the / URI; and (3) append arbitrary data to a file via a .. (dot dot) in an account name, when requesting a URI composed of a "/?%0a" sequence followed by the data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-0405
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.rejetto.com/hfs/?f=wn
- http://www.securityfocus.com/bid/27423
- http://securityreason.com/securityalert/3581
- http://www.securityfocus.com/archive/1/486873/100/0/threaded
- http://www.syhunt.com/advisories/hfshack.txt
- http://www.syhunt.com/advisories/hfs-1-log.txt
- http://secunia.com/advisories/28631
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39873
More from hfs
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.