Page 1 of 1

Possible server path disclosure on showlog.cgi

Posted: Wed May 15, 2019 3:20 am
by rajatbel
Sensitive data like "/usr/local/nagios/var/nagios.log" is seen on paged displayed with showlog.cgi
One or more fully qualified path names were found on this page.
From this information the attacker may learn the file system structure from the web server. This information can be used to conduct further attacks.
please prevent this information and others from being displayed to the user .

Re: Possible server path disclosure on showlog.cgi

Posted: Wed May 15, 2019 6:36 am
by scottwilkerson
This would be behind basic authentication where only people with credentials could access.