5
CVSSv2

CVE-2008-0410

Published: 29/01/2008 Updated: 15/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

HTTP File Server (HFS) prior to 2.2c allows remote malicious users to obtain configuration and usage details by using an id element such as <id>%version%</id> in HTTP Basic Authentication instead of a username and password, as demonstrated by placing this id element in the userinfo subcomponent of a URL.

Vulnerable Product Search on Vulmon Subscribe to Product

hfs http file server

Exploits

HFS versions 23 through 20 suffer from cross site scripting and information disclosure vulnerabilities ...
Syhunt HFSHack version 10b is an exploit for various vulnerabilities found in HFS versions 15 through 23 ...