HTTP File Server (HFS) before 2.2c allows remote attackers to append arbitrary text to the log file by using the base64 representation of this text during HTTP Basic Authentication.
References
Configurations
Information
Published : 2008-01-28 16:00
Updated : 2018-10-15 14:59
NVD link : CVE-2008-0408
Mitre link : CVE-2008-0408
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
hfs
- http_file_server