important · RCE
One unauthenticated multipart filename executes commands on HFS 2.4, outside the older 2.3m CVE scope.
Affects
Rejetto HTTP File Server 2.x, a Windows file-sharing web server.
The filename enters a rejected-upload response, survives sequential template substitution, escapes a quoting region, and exposes an exec macro to the dispatcher.
Detail and 3 sources
Public Python and Nuclei reproducers were reported to work repeatedly against the original 2.4 RC7 binary, and upload permission is unnecessary.
This is a distinct sink from CVE-2024-23692, and no patch is available.
Sources