Nessus Plugin #11230

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

Stronghold Swish

Family:
CGI abuses
Category:
infos
Copyright:
This script is Copyright (C) 2003 Randy Matz
Summary:
Checks for the presence of cgi-bin/search
Version:
$Revision: 1.5 $
Cve_id:
-
Bugtraq_id:
4785
Xrefs:
-
Description:

An information disclosure vulnerability was reported in a
sample script provided with Red Hat's Stronghold web server.
A remote user can determine the web root directory path.

A remote user can send a request to the Stronghold sample script
swish to cause the script to reveal the full path to the webroot directory.

Apparently, swish may also display system-specific information in the
HTML returned by the script

Solution : remove it
Risk factor : Low
Generiert am 27.04.2005 um 18:49:54 Uhr.