 |
|
HTTP_ID command attempt
|
| |
Code:
p627
Severity: Warning
Description: Attempted id command access via web
Impact:
Attempt to gain information on users and groups that exist on the host
using the id command.
Corrective: Webservers should not be allowed to view or execute files and binaries outside of it's designated web root or cgi-bin.
|