|
|
|
|
|
|
|
| |
Multiple Web Server finger CGI Information Disclosure |
|
| This script is Copyright (C) 1999-2010 Tenable Network Security, Inc. |
|
|
| Family | CGI abuses |
| Nessus Plugin ID | 10071 (finger_cgi.nasl) |
| Bugtraq ID |
|
| CVE ID |
|
|
| Description: |
Synopsis :
An application on the remote web server is leaking information.
Description :
The 'finger' CGI is installed. This can be used by a remote attacker
to enumerate accounts on the system. Such information is typically
valuable in conducting additional, more focused attacks.
Solution :
Remove the script from /cgi-bin.
Risk factor :
Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
|
|
|
|
|
|