Multiple Web Server ~nobody/ Request Arbitrary File Access

Medium Nessus Plugin ID 10484


The remote web server is affected by an information disclosure vulnerability.


It is possible to access arbitrary files on the remote web server by appending ~nobody/ in front of their name (as in ~nobody/etc/passwd).

This problem is due to a misconfiguration in the web server that sets 'UserDir' or its equivalent to './'.


If using Apache, set 'UserDir' to 'public_html/' or something else.

If using lighttpd, upgrade to version 1.4.19 or later.

Otherwise, contact the web server vendor.

Plugin Details

Severity: Medium

ID: 10484

File Name: httpd_nobody.nasl

Version: $Revision: 1.19 $

Type: remote

Family: Web Servers

Published: 2000/08/01

Modified: 2015/09/24

Dependencies: 10107

Risk Information

Risk Factor: Medium


Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

Exploited by Nessus: true

Vulnerability Publication Date: 2000/01/01

Reference Information

OSVDB: 383