This application requires Javascript for optimal performance.

Test-cgi.Probe

Release Date

Mar 09, 2010

Severity

low

Impact

System Compromise: Remote attackers can gain sensitive information from vulnerable systems.

Description

This indicates an attack attempt against a remote information-disclosure vulnerability in the test-cgi program.

A vulnerability has been reported in the test-cgi program that may allow an attacker to list files on a vulnerable server. This is possible because the user input filters fail to properly sanitize the URL that is passed to tje test-cgi program. An attacker may gain sensitive information by sending a crafted HTTP request.

Affected Products

test-cgi

Recommended Actions

Currently we are not aware of any officially supplied patch for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-1999-0070

Reference/s

http://insecure.org/sploits/test-cgi.html
http://insecure.org/sploits/test-cgi.server_protocol.html

Reference: VID-18159