| ID | CVE-2001-0834 | ||||||
| Sažetak | htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read arbitrary files by uploading an alternate configuration file that specifies the target file. | ||||||
| Reference |
|
||||||
| CVSS |
|
||||||
| Pristup |
|
||||||
| Impact |
|
||||||
| CVSS vektor | AV:N/AC:L/Au:N/C:P/I:N/A:P | ||||||
| Zadnje važnije ažuriranje | 10-10-2017 - 01:29 | ||||||
| Objavljeno | 06-12-2001 - 05:00 |

