Family: Remote file access --> Category: infos
thttpd ssi file retrieval Vulnerability Scan
Vulnerability Scan Summary
thttpd ssi flaw
Detailed Explanation for this Vulnerability Test
The remote HTTP server
allows a possible hacker to read arbitrary files
on the remote web server, by employing a
weakness in an included ssi package, by
prepending pathnames with %2e%2e/ (hex-
encoded ../) to the pathname.
will return /etc/passwd.
Solution: upgrade to version 2.20 of thttpd.
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.