Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Remote file access --> Category: infos

thttpd ssi file retrieval Vulnerability Scan


Vulnerability Scan Summary
thttpd ssi flaw

Detailed Explanation for this Vulnerability Test
The remote HTTP server
allows a possible hacker to read arbitrary files
on the remote web server, by employing a
weakness in an included ssi package, by
prepending pathnames with %2e%2e/ (hex-
encoded ../) to the pathname.
Example:
GET /cgi-bin/ssi//%2e%2e/%2e%2e/etc/passwd

will return /etc/passwd.

Solution: upgrade to version 2.20 of thttpd.

Threat Level: High

Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.