This script is Copyright (C) 2012-2014 Tenable Network Security, Inc.
The remote Gentoo host is missing one or more security-related
The remote host is affected by the vulnerability described in GLSA-201206-27
(mini_httpd: Arbitrary code execution)
mini_httpd does not properly check for shell escapes when parsing HTTP
A remote attacker could send specially crafted HTTP requests, possibly
resulting in execution of arbitrary code with the privileges of the
process, or allowing for overwriting of files.
There is no known workaround at this time.
See also :
Gentoo discontinued support for mini_httpd. We recommend that users
# emerge --unmerge 'www-servers/mini_httpd'
Risk factor :
Medium / CVSS Base Score : 5.0
CVSS Temporal Score : 4.1
Public Exploit Available : true