RaidenHTTPD Crafted Request Script Source Disclosure
Medium Nessus Plugin ID 21015
SynopsisThe remote web server suffers from an information disclosure flaw.
DescriptionThe remote host is running RaidenHTTPD, a web server for Windows.
According to its banner, the version of RaidenHTTPD installed on the remote Windows host fails to properly validate filename extensions in URLs. A remote attacker may be able to leverage this issue to disclose the source of scripts hosted by the affected application using specially crafted requests with dot, space, and slash characters.
SolutionUpgrade to RaidenHTTPD version 1.1.48 or later.