HTTP File Server before 2.3c is susceptible to remote command execution. The findMacroMarker function in parserLib.pas allows an attacker to execute arbitrary programs via a %00 sequence in a search action. Therefore, an attacker can obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
View the template here CVE-2014-6287.yaml
Lab | Machine | Link |
---|---|---|
Hack The Box | Optimum | Go to Practice |
References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6287