Skip to finding
important · RCE

One unauthenticated multipart filename executes commands on HFS 2.4, outside the older 2.3m CVE scope.

Affects

Rejetto HTTP File Server 2.x, a Windows file-sharing web server.

The filename enters a rejected-upload response, survives sequential template substitution, escapes a quoting region, and exposes an exec macro to the dispatcher.

Detail and 3 sources

Public Python and Nuclei reproducers were reported to work repeatedly against the original 2.4 RC7 binary, and upload permission is unnecessary.

This is a distinct sink from CVE-2024-23692, and no patch is available.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 29, 2026