|
|
|
|
|
|
|
| |
IRIX wrap CGI Traversal Arbitrary Directory Listing |
|
| This script is Copyright (C) 1999-2010 Tenable Network Security, Inc. |
|
|
| Family | CGI abuses |
| Nessus Plugin ID | 10317 (wrap.nasl) |
| Bugtraq ID | 373
|
| CVE ID | CVE-1999-0149
|
|
| Description: |
Synopsis :
The remote web server contains a CGI script that is prone to
information disclosure.
Description :
The 'wrap' CGI is installed. This CGI allows anyone to get a listing
for any directory with mode +755.
Note that not all implementations of 'wrap' are vulnerable.
See also :
http://seclists.org/lists/bugtraq/1997/Apr/0076.html
Solution :
Remove this CGI script.
Risk factor :
Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
|
|
|
|
|
|