CVE-2000-1191
5
CVSS Score
Medium
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
Link copied!
Description
htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Confidentiality
P
Integrity
None
Availability
None
Affected Software Configurations
- a htdig_project htdig * * * * * * * *
- a htdig_project htdig 3.2.0 beta1 * * * * * *
Weaknesses (CWE)
- CWE-209
References & External Links
- http://www.securiteam.com/exploits/htDig_reveals_web_server_configuration_paths.html
- http://www.securityfocus.com/bid/4366
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7367
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10526
- http://www.securiteam.com/exploits/htDig_reveals_web_server_configuration_paths.html
- http://www.securityfocus.com/bid/4366
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7367
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10526
External Resources
CVE History Timeline
Jan 01, 2004 05:00
Initial Analysis
Jul 11, 2017 01:29
CVE Modified
Oct 19, 2017 01:29
CVE Modified
Dec 09, 2020 15:58
Modified Analysis
May 14, 2024 01:17
CVE Modified
Nov 20, 2024 23:34
CVE Modified