Backup Files Disclosure

medium Nessus Plugin ID 11411


It is possible to retrieve file backups from the remote web server.


By appending various suffixes (ie: .old, .bak, ~, etc...) to the names of various files on the remote host, it seems possible to retrieve their contents, which may result in disclosure of sensitive information.


Ensure the files do not contain any sensitive information, such as credentials to connect to a database, and delete or protect those files that should not be accessible.

See Also

Plugin Details

Severity: Medium

ID: 11411

File Name: bakfiles.nasl

Version: 1.46

Type: remote

Family: CGI abuses

Published: 3/17/2003

Updated: 1/19/2021

Risk Information


Risk Factor: Medium

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N