5
CVSSv2

CVE-2000-0208

Published: 29/02/2000 Updated: 10/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The htdig (ht://Dig) CGI program htsearch allows remote malicious users to read arbitrary files by enclosing the file name with backticks (`) in parameters to htsearch.

Vulnerable Product Search on Vulmon Subscribe to Product

htdig htdig 3.1.3

htdig htdig 3.2.0b1

htdig htdig 3.1.1

htdig htdig 3.1.2

htdig htdig 3.1.4

Exploits

source: wwwsecurityfocuscom/bid/1026/info ht://dig is a web content search engine for Unix platforms The software is set up to allow for file inclusion from configuration files Any string surrounded by the opening singlw quote character ( ` ) is taken as a path to a file for inclusion, for example: some_parameter: `var/htdig/some_file` ...