A potentially dangerous file was found on the web server. While there is no known vulnerability or exploit associated with this file, it has been found in logs after web servers have come under attack from unknown sources and software. This may indicate the presence of an undisclosed vulnerability that is being exploited in the wild.
Classification
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure,
Misconfiguration,
Other
Impact:
Loss of Confidentiality,
Loss of Integrity,
Loss of Availability
Exploit:
Exploit Unknown
OSVDB:
Best Practice
Solution
If the file or directory contains sensitive information, remove the files from the web server or password protect them. If CGI programs contain exploits, remove the files or correct the vulnerability.