CVE-2008-0407

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
29/01/2008
Last modified:
09/04/2025

Description

HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more difficult for an administrator to determine who made a remote request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hfs:http_file_server:*:*:*:*:*:*:*:* 2.2b (including)