The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.
https://github.com/Sweatzer/Lab-WriteUps
https://github.com/R3fr4kt/Optimum
https://github.com/jagg3rsec/CVE-2014-6287
https://github.com/JoaZ94/rejjeto_hfs-rce-exploit-cve-2014-6287
https://github.com/nika0x38/CVE-2014-6287
https://github.com/uttambodara/Awesome-Hacking-Learning-Path
https://github.com/sage954526/HFS_EXPLOIT_PROJECT
https://github.com/francescobrina/hfs-cve-2014-6287-exploit
https://github.com/randallbanner/Rejetto-HTTP-File-Server-HFS-2.3.x---Remote-Command-Execution
https://github.com/QuantumPhysx2/CVE-Cheat-Sheet
https://github.com/hadrian3689/rejetto_hfs_rce
https://github.com/mrintern/thm_steelmountain_CVE-2014-6287
https://github.com/Mr-Intern/thm_steelmountain_CVE-2014-6287
https://github.com/wizardy0ga/THM-Steel_Mountain-CVE-2014-6287
https://github.com/SlizBinksman/THM-Steel_Mountain-CVE-2014-6287
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-6287
https://github.com/rapid7/metasploit-framework/pull/3793
http://packetstormsecurity.com/files/161503/HFS-HTTP-File-Server-2.3.x-Remote-Code-Execution.html
http://packetstormsecurity.com/files/128243/HttpFileServer-2.3.x-Remote-Command-Execution.html