CVE-2000-1191 Information
Feb 14, 2021
cve
Description
htsearch program in htDig 3.2 beta 3.1.6 3.1.5 and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter which generates an error message that includes the full path.
Reference
http://www.securiteam.com/exploits/htDig_reveals_web_server_configuration_paths.html http://www.securityfocus.com/bid/4366 https://exchange.xforce.ibmcloud.com/vulnerabilities/7367 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A10526
Share on: