HFS versions 1.5g through 2.3 suffer from username spoofing and log injection vulnerabilities.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/62933/hfs-spoof.txt
Source: https://packetstormsecurity.com/files/62933/hfs-spoof.txt.html