Backup Files Disclosure

medium Nessus Plugin ID 11411

Synopsis

It is possible to retrieve file backups from the remote web server.

Description

By appending various suffixes (ie: .old, .bak, ~, etc...) to the names of various files on the remote host, it seems possible to retrieve their contents, which may result in disclosure of sensitive information.

Solution

Ensure the files do not contain any sensitive information, such as credentials to connect to a database, and delete or protect those files that should not be accessible.

See Also

http://www.nessus.org/u?8f3302c6

Plugin Details

Severity: Medium

ID: 11411

File Name: bakfiles.nasl

Version: 1.47

Type: remote

Family: CGI abuses

Published: 3/17/2003

Updated: 7/10/2023

Supported Sensors: Nessus

Risk Information

CVSS Score Rationale: Score from an in depth analysis done by tenable

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: manual