CVE-2000-1191

Publication date

2001-09-12 04:00:00

Family

mitre

State

PUBLISHED

Description

htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path.