First published: Tue Feb 29 2000(Updated: )
The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name with backticks (`) in parameters to htsearch.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ht://Dig | =3.2.0b1 | |
ht://Dig | =3.1.4 | |
ht://Dig | =3.1.3 | |
ht://Dig | =3.1.1 | |
ht://Dig | =3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0208 is classified as a security vulnerability that allows remote file access, potentially leading to information disclosure.
To fix CVE-2000-0208, upgrade to a patched version of ht://Dig that addresses the arbitrary file read issue.
CVE-2000-0208 affects ht://Dig versions 3.1.1, 3.1.2, 3.1.3, 3.1.4, and 3.2.0b1.
CVE-2000-0208 enables remote attackers to read arbitrary files from the server by exploiting the htsearch CGI program.
CVE-2000-0208 was reported in the ht://Dig CGI program specifically related to how it handles parameters in the htsearch function.