Test-cgi sample CGI script allows remote retrieval of file listings |
---|
Risk Level: | Medium | Check or Attack Name: vulntestcgi |
---|---|---|
Platforms: | NCSA Servers: Old, Apache: Old, Common Gateway Interface (CGI) | |
Description: | The test-cgi program shipped with older NCSA and Apache web server packages contains a vulnerability that allows remote users to view listings of files on your system. Exploit information for this hole has been widely distributed. |
|
Remedy: | Remove test-cgi, in addition to any other example CGI scripts, from your cgi-bin directory. If these scripts exist on your system, you may be running an outdated server and should upgrade to the latest version offered by your vendor. |
|
References: | L0pht Security Advisory, test-cgi vulnerability in certain setups, http://www.l0pht.com/advisories/test-cgi-vulnerability |
Know Your Risks |