Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Apache: Users

Directory Traversal Vulnerability

 

 

Apache users RSS feed   Index | Next | Previous | View Threaded


backus at whimsy

Nov 24, 2009, 11:51 AM

Post #1 of 2 (276 views)
Permalink
Directory Traversal Vulnerability

Our crack security team scanned my web server with QualysGuard
Enterprise. It found a "Gneric Web Server Directory Traversal
Vulnerability." I'm at a loss to fix this, httpd -v returns:

Server version: Apache/2.2.3
Server built: Nov 10 2009 09:06:57

I'm on RHEL 5 with current patches. Can anyone point me in the
direction of a fix?

Thanks,
Steve
--
Steven J. Backus Computer Specialist
University of Utah E-Mail: steven.backus [at] utah
Genetic Epidemiology Alternate: backus [at] math
391 Chipeta Way -- Suite D Office: 801.587.9308
Salt Lake City, UT 84108-1266 http://www.math.utah.edu/~backus

---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe [at] httpd
" from the digest: users-digest-unsubscribe [at] httpd
For additional commands, e-mail: users-help [at] httpd


j.zuckerman at gmail

Nov 24, 2009, 12:38 PM

Post #2 of 2 (268 views)
Permalink
Re: Directory Traversal Vulnerability [In reply to]

On Tue, Nov 24, 2009 at 11:51 AM, Steven Backus
<backus [at] whimsy> wrote:
> Our crack security team scanned my web server with QualysGuard
> Enterprise.  It found a "Gneric Web Server Directory Traversal
> Vulnerability."  I'm at a loss to fix this, httpd -v returns:
>
> Server version: Apache/2.2.3
> Server built:   Nov 10 2009 09:06:57
>
> I'm on RHEL 5 with current patches.  Can anyone point me in the
> direction of a fix?
>
> Thanks,
>  Steve
> --
> Steven J. Backus                        Computer Specialist
> University of Utah                      E-Mail:  steven.backus [at] utah
> Genetic Epidemiology                    Alternate:  backus [at] math
> 391 Chipeta Way -- Suite D              Office:  801.587.9308
> Salt Lake City, UT 84108-1266           http://www.math.utah.edu/~backus
>
> ---------------------------------------------------------------------
> The official User-To-User support forum of the Apache HTTP Server Project.
> See <URL:http://httpd.apache.org/userslist.html> for more info.
> To unsubscribe, e-mail: users-unsubscribe [at] httpd
>   "   from the digest: users-digest-unsubscribe [at] httpd
> For additional commands, e-mail: users-help [at] httpd
>
>

http://tinyurl.com/ylzn5g8

third link from the top bro

---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe [at] httpd
" from the digest: users-digest-unsubscribe [at] httpd
For additional commands, e-mail: users-help [at] httpd

Apache users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.