HTTP View source vulnerability |
---|
Risk Level: | Medium | Check or Attack Name: ViewSource |
---|---|---|
Platforms: | Common Gateway Interface (CGI) | |
Description: | The view-source CGI script distributed with some web servers and the SCO Skunkware CD-ROM contains a vulnerability that could allow a remote attacker to view files on the server. The attacker is limited to reading files accessible to the user owning the server process, usually nobody. |
|
Remedy: | Remove the view-source script from the cgi-bin directory on your web server. |
|
References: | BUGTRAQ Mailing List, view-source, http://www.netspace.org/cgi-bin/wa?A2=ind9702B&L=bugtraq&P=R64 |
Know Your Risks |