Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

ht://Dig Configuration File Path Disclosure Vulnerability

ht://Dig is a freely available, open source search engine. It is developed and maintained by the ht://Dig project, and functions on the Unix and Linux operating systems.

When the htsearch component of ht://Dig is executed with a 'config' variable supplied, and erroneous or nonsensical data supplied as the argument to the config variable, ht://Dig returns the full path of the configuration file directory for ht://Dig. Additionally, the 'config' variable being accessible by any user may allow the ht://Dig program to load arbitrary files as configuration.







 

Privacy Statement
Copyright 2009, SecurityFocus