NCDSA HTTPd nph-test-cgi Arbitrary Directory Listing
Medium Nessus Plugin ID 10165
SynopsisThe remote web server contains a CGI script that is affected by information disclosure vulnerabilities.
DescriptionThe remote web server contains the 'nph-test-cgi' test script, which is included by default with some web servers.
The version of this script on the remote host fails to quote input to several environment variables, such as 'QUERY_STRING', before echoing it back as part of a shell script. An unauthenticated attacker can leverage this issue to list the contents of directories on the remote host, subject to the permissions of the web server user id.
SolutionDisable or delete the CGI script.