Test-cgi sample CGI script allows remote retrieval of file listings

Risk Level: Medium risk vulnerability  Medium

Check or Attack Name: vulntestcgi

Platforms: NCSA Servers: Old, Apache: Old, Common Gateway Interface (CGI)
Description:

The test-cgi program shipped with older NCSA and Apache web server packages contains a vulnerability that allows remote users to view listings of files on your system. Exploit information for this hole has been widely distributed.

Remedy:

Remove test-cgi, in addition to any other example CGI scripts, from your cgi-bin directory. If these scripts exist on your system, you may be running an outdated server and should upgrade to the latest version offered by your vendor.

References:

L0pht Security Advisory, test-cgi vulnerability in certain setups, http://www.l0pht.com/advisories/test-cgi-vulnerability


X-Force Logo
Know Your Risks