12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IDS eventsSuspicious activity381HTTP HtSearch CGI Passwd AccessBase Event:Details:Response:HTTP_HTSEARCH_FILE_ACCESSHtdig is a Web content search engine for UNIX platforms. The software is set up to allow for fileinclusion from configuration files. Any string surrounded by the opening single quote character(‘) is taken as a path to a file for inclusion, for example:some_parameter:‘var/htdig/some_file’Htdig also allows included files to be specified by means of form input. Therefore, any Web user canspecify any file for inclusion into a variable.Administrators should upgrade to htdig version 3.1.5, which is fixed.Affected: The htDig Group htDig 3.1.1The htDig Group htDig 3.1.2The htDig Group htDig 3.1.3The htDig Group htDig 3.1.4The htDig Group htDig 3.2.0b1False Positives: None known.<strong>Reference</strong>s <strong>Security</strong> Focus BID: 1026Htdig Home Page

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!