Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7c6m-w964-4jjh

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path.

htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path.

EPSS

Процентиль: 83%
0.01998
Низкий

Дефекты

CWE-209

Связанные уязвимости

redhat
около 25 лет назад

htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path.

nvd
почти 24 года назад

htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path.

EPSS

Процентиль: 83%
0.01998
Низкий

Дефекты

CWE-209