WebLog Information Disclosure

low Nessus Network Monitor Plugin ID 2493

Synopsis

The remote host may give an attacker information useful for future attacks.

Description

The remote host is running the WebLog report generator. This application parses the web logs and gives information regarding files accessed, errors, site referers and more. An attacker perusing this page would be able to gather information useful in further attacks against the web server.

Solution

Use ACLs to protect the WebLog Reports.

Plugin Details

Severity: Low

ID: 2493

Family: Web Servers

Published: 1/6/2005

Updated: 1/15/2016