SCAN: htgrep Access
This signature detects HTTP requests to run the Htgrep CGI script on the Web server. Attackers can use this Perl script to query any document accessible to the Web server on a paragraph-by-paragraph basis.
Extended Description
Htgrep CGI program allows remote attackers to read arbitrary files by specifying the full pathname in the hdr parameter.
Affected Products
Oscar_nierstrasz htgrep
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Oscar_nierstrasz
5.0