Dedicated HTTP file-server software has produced memorable remote code execution. HTTP File Server (HFS), widely used for quick file sharing, has had template-expression injection where a crafted request value is evaluated by the server's macro engine and runs commands. Other file-server applications have similar upload, traversal, and injection flaws reachable over HTTP.
Common HTTP file-server RCE classes:
- HFS: server-side template/macro expression injection in request handling
- filebrowser and similar: authentication and upload flaws
- Misconfigured application file managers: traversal and upload to execution
Exploitation notes#
- Fingerprint the file-server product and version from the server banner and page markup before selecting a technique.
- HFS template injection is unauthenticated and reliable on affected versions, yielding command execution as the server user.
- Where no named flaw applies, fall back to the generic File upload to RCE and Path traversal.