The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-6287