CVE-2008-0410
HTTP File Server (HFS) before 2.2c allows remote attackers to obtain configuration and usage details by using an id element such as <id>%version%</id> in HTTP Basic Authentication instead of a username and password, as demonstrated by placing this id…
Does this matter?
Lower severity and a low EPSS score (1.80%). Track it; it rarely justifies an emergency change on its own.
Description
HTTP File Server (HFS) before 2.2c allows remote attackers to obtain configuration and usage details by using an id element such as <id>%version%</id> in HTTP Basic Authentication instead of a username and password, as demonstrated by placing this id element in the userinfo subcomponent of a URL.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.80% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- hfs/http file server
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/28631Vendor Advisory
- http://securityreason.com/securityalert/3583
- http://www.rejetto.com/hfs/?f=wnExploit
- http://www.securityfocus.com/archive/1/486872/100/0/threaded
- http://www.securityfocus.com/bid/27423
- http://www.syhunt.com/advisories/hfs-1-template.txt
- http://www.syhunt.com/advisories/hfshack.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39871
- http://secunia.com/advisories/28631Vendor Advisory
- http://securityreason.com/securityalert/3583
- http://www.rejetto.com/hfs/?f=wnExploit
- http://www.securityfocus.com/archive/1/486872/100/0/threaded
- http://www.securityfocus.com/bid/27423
- http://www.syhunt.com/advisories/hfs-1-template.txt
- http://www.syhunt.com/advisories/hfshack.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39871
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.