Stronghold Secure Web Server Information Disclosure Vulnerability
BID:3577
Info
Stronghold Secure Web Server Information Disclosure Vulnerability
| Bugtraq ID: | 3577 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 23 2001 12:00AM |
| Updated: | Nov 23 2001 12:00AM |
| Credit: | Discovered by Madalina Andrei and Reda Zitouni of Vigilante and posted to the BugTraq mailing list on November 23, 2001. |
| Vulnerable: |
Redhat Stronghold 3.0 Redhat Stronghold 2.4 Redhat Stronghold 2.3 |
| Not Vulnerable: | |
Discussion
Stronghold Secure Web Server Information Disclosure Vulnerability
Redhat Stronghold Secure Web Server is a web server based on the Apache source and designed to be robust and secure.
The default installation of Stronghold supports urls designed to help administrate the system by displaying server information, including the httpd.conf file. A malicious user viewing this information may be able to use it to stage further attacks on the server. The relevant urls are:
http://target/stronghold-info
http://target/stronghold-status
These urls are not enabled in the default installation.
Redhat Stronghold Secure Web Server is a web server based on the Apache source and designed to be robust and secure.
The default installation of Stronghold supports urls designed to help administrate the system by displaying server information, including the httpd.conf file. A malicious user viewing this information may be able to use it to stage further attacks on the server. The relevant urls are:
http://target/stronghold-info
http://target/stronghold-status
These urls are not enabled in the default installation.
References
Stronghold Secure Web Server Information Disclosure Vulnerability
References:
References:
- Stronghold Secure Web Server (RedHat)