The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name with backticks (`) in parameters to htsearch.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Htdig | Htdig | 3.1.1 (including) | 3.1.1 (including) |
Htdig | Htdig | 3.1.2 (including) | 3.1.2 (including) |
Htdig | Htdig | 3.1.3 (including) | 3.1.3 (including) |
Htdig | Htdig | 3.1.4 (including) | 3.1.4 (including) |
Htdig | Htdig | 3.2.0b1 (including) | 3.2.0b1 (including) |