Synopsis
The remote web server discloses information about its status.
Description
It is possible to obtain an overview of the Perl interpreter embedded in the remote Apache server. This overview includes information such as loaded modules, Perl configuration, and settings of environment variables.
Solution
Ensure that access to Apache::Status / Apache2::Status is limited to valid users / hosts or, if it's not needed, update Apache's configuration file to disable use of this handler.
Plugin Details
File Name: mod_perl_status.nasl
Configuration: Enable thorough checks
Supported Sensors: Nessus
Vulnerability Information
Required KB Items: www/apache
Excluded KB Items: Settings/disable_cgi_scanning
Exploited by Nessus: true