|
Family: Gain a shell remotely --> Category: infos
Cherokee directory traversal flaw Vulnerability Scan
Vulnerability Scan Summary Checks for version of Cherokee
Detailed Explanation for this Vulnerability Test
The remote host is running Cherokee - a fast and tiny web server.
The remote version of this software is vulnerable to directory
traversal flaw when appending a '../' sequence to the web request.
Additionally, this version fails to drop root rights after it binds
to listen port.
Remote attacker can then submit specially crafted web request to
browse any file on the server with root rights.
Solution : Upgrade to Cherokee 0.2.8 or newer
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|