CVE
- Id
- 2401
- CVE No.
- CVE-2000-0832
- Status
- Candidate
- Description
- Htgrep CGI program allows remote attackers to read arbitrary files by specifying the full pathname in the hdr parameter.
- Phase
- Modified (20010910-01)
- Votes
- ACCEPT(2) Baker, Collins | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Cole, Wall
- Comments
- Frech> XF:htgrep-cgi-view-files(5476) | Collins> http://www.iam.unibe.ch/~scg/Src/Doc/ | Christey> The change log for htgrep acknowledges the problem, but it | says that the qry tag is also affected. CD:SF-LOC says that | multiple problems of the same type in the same version should | be combined, so this candidate should get a "soft recast" | and qry should be added to the description.