|
|
Info |
Last Modified |
| 7 months ago |
|
|
|
|
Description |
Many web servers contain a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an administrator uses explicitly granular directives within the robots.txt file, which may disclose sensitive documents or directories. This may allow an attacker to gain knowledge of the sensitive information and use it to gain access.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
OSVDB:
Web Related
|
|
Solution |
Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround: Ensure that no sensitive information is stored in the robots.txt file.
|
|
Products |
|
Web Servers
 |
All Versions |
|
|
|
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|