CVE

Id
2401  
CVE No.
CVE-2000-0832  
Status
Candidate  
Description
Htgrep CGI program allows remote attackers to read arbitrary files by specifying the full pathname in the hdr parameter.  
Phase
Modified (20010910-01)  
Votes
ACCEPT(2) Baker, Collins | MODIFY(1) Frech | NOOP(4) Armstrong, Christey, Cole, Wall  
Comments
Frech> XF:htgrep-cgi-view-files(5476) | Collins> http://www.iam.unibe.ch/~scg/Src/Doc/ | Christey> The change log for htgrep acknowledges the problem, but it | says that the qry tag is also affected. CD:SF-LOC says that | multiple problems of the same type in the same version should | be combined, so this candidate should get a "soft recast" | and qry should be added to the description.