Total vulnerabilities in the database
htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path.
Software | From | Fixed in |
---|---|---|
htdig_project / htdig | - | 3.1.6.x |
htdig_project / htdig | 3.2.0-beta1 | 3.2.0-beta1.x |