|
Family: Remote file access --> Category: infos
thttpd ssi file retrieval Vulnerability Scan
Vulnerability Scan Summary thttpd ssi flaw
Detailed Explanation for this Vulnerability Test
The remote HTTP server
allows a possible hacker to read arbitrary files
on the remote web server, by employing a
weakness in an included ssi package, by
prepending pathnames with %2e%2e/ (hex-
encoded ../) to the pathname.
Example:
GET /cgi-bin/ssi//%2e%2e/%2e%2e/etc/passwd
will return /etc/passwd.
Solution: upgrade to version 2.20 of thttpd.
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|