Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.111108
Category:Web application abuses
Title:Linux Home Folder Accessible (HTTP)
Summary:The script attempts to identify files of a linux home folder; accessible at the webserver.
Description:Summary:
The script attempts to identify files of a linux home folder
accessible at the webserver.

Vulnerability Insight:
Currently the script is checking for the following files:

- /.ssh/authorized_keys

- /.ssh/config

- /.ssh/known_hosts

- /.ssh/identity

- /.ssh/id_rsa

- /.ssh/id_rsa.pub

- /.ssh/id_dsa

- /.ssh/id_dsa.pub

- /.ssh/id_dss

- /.ssh/id_dss.pub

- /.ssh/id_ecdsa

- /.ssh/id_ecdsa.pub

- /.ssh/id_ed25519

- /.ssh/id_ed25519.pub

- /.mysql_history

- /.sqlite_history

- /.psql_history

- /.sh_history

- /.bash_history

- /.profile

- /.bashrc

Vulnerability Impact:
Based on the information provided in these files an attacker
might be able to gather additional info.

Solution:
A users home folder shouldn't be accessible via a webserver.
Restrict access to it or remove it completely.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

CopyrightCopyright (C) 2016 SCHUTZWERK GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.