SCAN: htgrep Access

This signature detects HTTP requests to run the Htgrep CGI script on the Web server. Attackers can use this Perl script to query any document accessible to the Web server on a paragraph-by-paragraph basis.

Extended Description

Htgrep CGI program allows remote attackers to read arbitrary files by specifying the full pathname in the hdr parameter.

Affected Products

Oscar_nierstrasz htgrep

Short Name
SCAN:MISC:HTTP:HTGREP-ACCESS
Severity
Info
Recommended
False
Recommended Action
None
Category
SCAN
Keywords
Access CVE-2000-0832 htgrep
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Rarely
Vendors

Oscar_nierstrasz

CVSS Score

5.0

Found a potential security threat?