HTTP File Server (HFS) before 2.2c allows remote attackers to append arbitrary text to the log file by using the base64 representation of this text during HTTP Basic Authentication.
References
Configurations
History
No history.
Information
Published : 2008-01-29 00:00
Updated : 2024-02-04 17:13
NVD link : CVE-2008-0408
Mitre link : CVE-2008-0408
CVE.ORG link : CVE-2008-0408
JSON object : View
Products Affected
hfs
- http_file_server
CWE
CWE-287
Improper Authentication