Scan summary

Scan information
Start time28-9-2006, 21:56
Finish time30-9-2006, 11:00
Scan time 2223 minutes
Server bannerApache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Operating systemUnix
WebServer technologiesPHP
Alerts summary
Alerts found
Total alerts found 356  
High 79
Medium 16
Low 261
Informational 0
NameSeverityAffects
1. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/aspx/connector.aspx
2. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/io.asp
3. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/io.asp
4. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/io.asp
5. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/util.asp
6. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/util.asp
7. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/util.asp
8. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/basexml.asp
9. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/aspx/connector.aspx
10. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp
11. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/aspx/connector.aspx
12. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/aspx/connector.aspx
13. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/perl/connector.cgi
14. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/perl/connector.cgi
15. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/perl/connector.cgi
16. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/perl/connector.cgi
17. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/util.asp
18. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/config.asp
19. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/class_upload.asp
20. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/class_upload.asp
21. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/class_upload.asp
22. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/class_upload.asp
23. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/commands.asp
24. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/commands.asp
25. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp
26. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/commands.asp
27. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp
28. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/config.asp
29. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/config.asp
30. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/config.asp
31. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp
32. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp
33. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp
34. Script source code disclosure High /include/fckeditor/fckconfig.js
35. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/commands.asp
36. Script source code disclosure High /include/prototype-1.4.0/src/prototype.js
37. Script source code disclosure High /include/fckeditor/fckconfig.js
38. Script source code disclosure High /include/magpierss/rss_parse.inc
39. Script source code disclosure High /include/magpierss/rss_parse.inc
40. Script source code disclosure High /include/magpierss/rss_parse.inc
41. Script source code disclosure High /include/magpierss/rss_utils.inc
42. Script source code disclosure High /include/magpierss/rss_utils.inc
43. Script source code disclosure High /include/magpierss/rss_fetch.inc
44. Script source code disclosure High /include/magpierss/rss_utils.inc
45. Script source code disclosure High /include/magpierss/rss_fetch.inc
46. Script source code disclosure High /include/prototype-1.4.0/src/prototype.js
47. Script source code disclosure High /include/prototype-1.4.0/src/prototype.js
48. Script source code disclosure High /include/prototype-1.4.0/src/prototype.js
49. Script source code disclosure High /themes/bluelagoon/images/Thumbs.db
50. Script source code disclosure High /themes/bluelagoon/images/Thumbs.db
51. Script source code disclosure High /themes/bluelagoon/images/Thumbs.db
52. Script source code disclosure High /themes/bluelagoon/images/Thumbs.db
53. Script source code disclosure High /include/magpierss/rss_utils.inc
54. Script source code disclosure High /include/magpierss/extlib/Snoopy.class.inc
55. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp
56. Script source code disclosure High /include/fckeditor/fckconfig.js
57. Script source code disclosure High /include/install/images/Thumbs.db
58. Script source code disclosure High /include/install/images/Thumbs.db
59. Script source code disclosure High /include/install/images/Thumbs.db
60. Script source code disclosure High /include/install/images/Thumbs.db
61. Script source code disclosure High /include/magpierss/rss_parse.inc
62. Script source code disclosure High /include/magpierss/extlib/Snoopy.class.inc
63. Script source code disclosure High /include/fckeditor/fckconfig.js
64. Script source code disclosure High /include/magpierss/extlib/Snoopy.class.inc
65. Script source code disclosure High /include/magpierss/rss_cache.inc
66. Script source code disclosure High /include/magpierss/rss_cache.inc
67. Script source code disclosure High /include/magpierss/rss_cache.inc
68. Script source code disclosure High /include/magpierss/rss_cache.inc
69. Script source code disclosure High /include/magpierss/rss_fetch.inc
70. Script source code disclosure High /include/magpierss/rss_fetch.inc
71. Script source code disclosure High /include/magpierss/extlib/Snoopy.class.inc
72. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/basexml.asp
73. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/basexml.asp
74. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/basexml.asp
75. Script source code disclosure High /include/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.pl
76. Script source code disclosure High /include/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.pl
77. Script source code disclosure High /include/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.pl
78. Script source code disclosure High /include/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.pl
79. Script source code disclosure High /include/fckeditor/editor/filemanager/browser/default/connectors/asp/io.asp
80. Source code disclosure Medium /include/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.pl
81. PHPSESSID session fixation Medium /
82. Source code disclosure Medium /include/fckeditor/editor/filemanager/browser/default/connectors/aspx/connector.aspx
83. Source code disclosure Medium /include/fckeditor/editor/filemanager/browser/default/connectors/asp/util.asp
84. Source code disclosure Medium /include/fckeditor/editor/filemanager/browser/default/connectors/asp/io.asp
85. Source code disclosure Medium /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp
86. Source code disclosure Medium /include/fckeditor/editor/filemanager/browser/default/connectors/asp/config.asp
87. Source code disclosure Medium /include/fckeditor/editor/filemanager/browser/default/connectors/asp/commands.asp
88. Source code disclosure Medium /include/fckeditor/editor/filemanager/browser/default/connectors/asp/class_upload.asp
89. Apache 2.x version older than 2.0.55 Medium Web Server
90. Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability Medium Web Server
91. Source code disclosure Medium /include/fckeditor/editor/filemanager/browser/default/connectors/asp/basexml.asp
92. Full path disclosure Medium /index.php
93. Source code disclosure Medium /include/fckeditor/editor/filemanager/browser/default/connectors/perl/connector.cgi
94. Source code disclosure Medium /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp (GET Command=FileUpload&Type=File&CurrentFolder=/)
95. Full path disclosure Medium /
96. Possible sensitive directories Low /test/
97. Possible sensitive directories Low /modules/Webmails/tmp/
98. Possible sensitive directories Low /include/prototype-1.4.0/test/
99. Possible sensitive directories Low /include/fckeditor/editor/filemanager/browser/default/connectors/asp/
100. Possible sensitive files Low /include/fckeditor/editor/filemanager/browser/default/connectors/test.html
101. Possible sensitive directories Low /include/database/
102. Possible sensitive directories Low /include/install/
103. Possible sensitive directories Low /install/
104. Possible sensitive directories Low /data/
105. Possible sensitive directories Low /include/
106. Directory listing found Low /include
107. Directory listing found Low /include (GET C=D;O=D)
108. Possible sensitive directories Low /database/
109. Directory listing found Low /include/images (GET C=D;O=A)
110. Directory listing found Low /include/js (GET C=S;O=D)
111. Directory listing found Low /include/js (GET C=M;O=D)
112. Directory listing found Low /include/js (GET C=N;O=A)
113. Directory listing found Low /include/js (GET C=D;O=A)
114. Directory listing found Low /include/js (GET C=S;O=A)
115. Directory listing found Low /include/js (GET C=M;O=A)
116. Directory listing found Low /include/js (GET C=N;O=D)
117. Directory listing found Low /include/js
118. Directory listing found Low /include/images (GET C=D;O=D)
119. Directory listing found Low /include/images (GET C=M;O=D)
120. Directory listing found Low /include (GET C=N;O=A)
121. Directory listing found Low /include/images (GET C=N;O=A)
122. Directory listing found Low /include (GET C=N;O=D)
123. Directory listing found Low /include/images (GET C=S;O=A)
124. Directory listing found Low /include/images (GET C=M;O=A)
125. Directory listing found Low /include/images (GET C=N;O=D)
126. Directory listing found Low /include/images
127. Directory listing found Low /include (GET C=M;O=D)
128. Broken links Low /modules/Emails/Emails.js
129. Directory listing found Low /include (GET C=S;O=D)
130. Directory listing found Low /include (GET C=D;O=A)
131. Directory listing found Low /include (GET C=S;O=A)
132. Directory listing found Low /include (GET C=M;O=A)
133. Directory listing found Low /include/images (GET C=S;O=D)
134. Directory listing found Low /include/js (GET C=D;O=D)
135. Broken links Low /modules/Accounts/Accounts.js
136. Broken links Low /modules/Users/{ORDER_BY}user_ip
137. Broken links Low /modules/Users/{ORDER_BY}login_time
138. Broken links Low /modules/Users/{ORDER_BY}logout_time
139. Broken links Low /modules/uploads/index.php
140. Broken links Low /modules/uploads/themes/style.css
141. Broken links Low /modules/uploads/index.php (GET module=uploads&action=add2db&return_module=; POST MAX_FILE_SIZE=1000000&return_module=&return_action=&return_id=&filename=&txtDescription=&save=%26nbsp%3BAttach%26nbsp%3B&cancel=Cancel)
142. File inputs accepted Low /include/fckeditor/editor/dialog/fck_flash.html
143. File inputs accepted Low /include/fckeditor/editor/dialog/fck_image.html
144. File inputs accepted Low /include/fckeditor/editor/dialog/fck_link.html
145. Broken links Low /modules/Users/index.php (GET module=Users&action=ListView&query=true&last_name=I)
146. Broken links Low /include/fckeditor/editor/dialog/fck_flash/fck_flash_preview.html
147. Broken links Low /modules/Users/index.php (GET module=Users&action=ListView&query=true&last_name=H)
148. File inputs accepted Low /include/fckeditor/editor/dialog/fck_flash.html
149. Directory listing found Low /include/scriptaculous (GET C=M;O=D)
150. File inputs accepted Low /include/fckeditor/editor/dialog/fck_image.html
151. File inputs accepted Low /include/fckeditor/editor/dialog/fck_link.html
152. Broken links Low /include/fckeditor/editor/dialog/common/common/fcknumericfield.htc
153. File inputs accepted Low /include/fckeditor/editor/filemanager/browser/default/frmupload.html
154. File inputs accepted Low /include/fckeditor/editor/filemanager/browser/default/connectors/test.html
155. File inputs accepted Low /include/fckeditor/editor/filemanager/browser/default/frmupload.html
156. File inputs accepted Low /include/fckeditor/editor/filemanager/browser/default/connectors/test.html
157. TRACE Method Enabled Low Web Server
158. Broken links Low /include/fckeditor/editor/dialog/fck_flash/fck_flash.js
159. Broken links Low /themes/alphagrey/include/style.css
160. Broken links Low /modules/Potentials/Potentials.js
161. Broken links Low /modules/Contacts/Contacts.js
162. Broken links Low /modules/Notes/Notes.js
163. Broken links Low /modules/Calendar/Calendar.js
164. Broken links Low /modules/Products/Products.js
165. Broken links Low /modules/Vendors/Vendors.js
166. Broken links Low /modules/PriceBooks/PriceBooks.js
167. Broken links Low /modules/Quotes/Quotes.js
168. Broken links Low /modules/Campaigns/Campaigns.js
169. Broken links Low /modules/Leads/Leads.js
170. Broken links Low /modules/Users/{ORDER_BY}user_name
171. File inputs accepted Low /modules/uploads/index.php
172. Broken links Low /style.css
173. Broken links Low /themes/woodspice/include/style.css
174. Broken links Low /modules/Users/index.php
175. Broken links Low /modules/Users/index.php (GET module=Users&action=ListView&advanced=true)
176. Broken links Low /modules/Users/index.php (GET module=Users&action=ListView&query=true&last_name=B)
177. Broken links Low /modules/Users/index.php (GET module=Users&action=ListView&query=true&last_name=A)
178. Broken links Low /modules/Users/index.php (GET module=Users&action=ListView&query=true&last_name=C)
179. Broken links Low /modules/Users/index.php (GET module=Users&action=ListView&query=true&last_name=D)
180. Broken links Low /modules/Users/index.php (GET module=Users&action=ListView&query=true&last_name=E)
181. Broken links Low /modules/Users/index.php (GET module=Users&action=ListView&query=true&last_name=F)
182. Broken links Low /modules/Users/index.php (GET module=Users&action=ListView&query=true&last_name=G)
183. Broken links Low /themes/bluelagoon/include/style.css
184. Directory listing found Low /include/fckeditor/editor/_source/internals (GET C=D;O=A)
185. Directory listing found Low /include/fckeditor/editor/_source/globals (GET C=S;O=A)
186. Directory listing found Low /include/fckeditor/editor/_source/globals (GET C=D;O=A)
187. Directory listing found Low /include/fckeditor/editor/_source/globals (GET C=N;O=A)
188. Directory listing found Low /include/fckeditor/editor/_source/globals (GET C=M;O=D)
189. Directory listing found Low /include/fckeditor/editor/_source/globals (GET C=S;O=D)
190. Directory listing found Low /include/fckeditor/editor/_source/globals (GET C=D;O=D)
191. Directory listing found Low /include/fckeditor/editor/_source/internals
192. Directory listing found Low /include/fckeditor/editor/_source/internals (GET C=N;O=D)
193. Directory listing found Low /include/fckeditor/editor/css (GET C=D;O=A)
194. Directory listing found Low /include/fckeditor/editor/_source/internals (GET C=S;O=A)
195. Directory listing found Low /include/fckeditor/editor/_source/globals
196. Directory listing found Low /include/fckeditor/editor/_source/internals (GET C=N;O=A)
197. Directory listing found Low /include/fckeditor/editor/_source/internals (GET C=M;O=D)
198. Directory listing found Low /include/fckeditor/editor/_source/internals (GET C=S;O=D)
199. Directory listing found Low /include/fckeditor/editor/_source/internals (GET C=D;O=D)
200. Directory listing found Low /include/fckeditor/editor/css
201. Directory listing found Low /include/fckeditor/editor/css (GET C=N;O=D)
202. Directory listing found Low /include/fckeditor/editor/css (GET C=M;O=A)
203. Directory listing found Low /include/scriptaculous (GET C=D;O=A)
204. Directory listing found Low /include/fckeditor/editor/_source/internals (GET C=M;O=A)
205. Directory listing found Low /include/fckeditor/editor/_source/commandclasses
206. Directory listing found Low /include/fckeditor/editor/_source (GET C=M;O=D)
207. Directory listing found Low /include/fckeditor/editor/_source/classes
208. Directory listing found Low /include/fckeditor/editor/_source/classes (GET C=N;O=D)
209. Directory listing found Low /include/fckeditor/editor/_source/classes (GET C=M;O=A)
210. Directory listing found Low /include/fckeditor/editor/_source/classes (GET C=S;O=A)
211. Directory listing found Low /include/fckeditor/editor/_source/classes (GET C=D;O=A)
212. Directory listing found Low /include/fckeditor/editor/_source/classes (GET C=N;O=A)
213. Directory listing found Low /include/fckeditor/editor/_source/classes (GET C=M;O=D)
214. Directory listing found Low /include/fckeditor/editor/_source/globals (GET C=M;O=A)
215. Directory listing found Low /include/fckeditor/editor/_source/classes (GET C=D;O=D)
216. Directory listing found Low /include/fckeditor/editor/_source/globals (GET C=N;O=D)
217. Directory listing found Low /include/fckeditor/editor/_source/commandclasses (GET C=N;O=D)
218. Directory listing found Low /include/fckeditor/editor/_source/commandclasses (GET C=M;O=A)
219. Directory listing found Low /include/fckeditor/editor/_source/commandclasses (GET C=S;O=A)
220. Directory listing found Low /include/fckeditor/editor/_source/commandclasses (GET C=D;O=A)
221. Directory listing found Low /include/fckeditor/editor/_source/commandclasses (GET C=N;O=A)
222. Directory listing found Low /include/fckeditor/editor/_source/commandclasses (GET C=M;O=D)
223. Directory listing found Low /include/fckeditor/editor/_source/commandclasses (GET C=S;O=D)
224. Directory listing found Low /include/fckeditor/editor/_source/commandclasses (GET C=D;O=D)
225. Directory listing found Low /include/fckeditor/editor/css (GET C=N;O=A)
226. Directory listing found Low /include/fckeditor/editor/_source/classes (GET C=S;O=D)
227. Directory listing found Low /include/fckeditor/editor/dialog/common/images (GET C=M;O=A)
228. Directory listing found Low /include/fckeditor/editor/dialog/common (GET C=N;O=D)
229. Directory listing found Low /include/fckeditor/editor/dialog/common (GET C=M;O=A)
230. Directory listing found Low /include/fckeditor/editor/dialog/common (GET C=S;O=A)
231. Directory listing found Low /include/fckeditor/editor/dialog/common (GET C=D;O=A)
232. Directory listing found Low /include/fckeditor/editor/dialog/common (GET C=N;O=A)
233. Directory listing found Low /include/fckeditor/editor/dialog/common (GET C=M;O=D)
234. Directory listing found Low /include/fckeditor/editor/dialog/common (GET C=S;O=D)
235. Directory listing found Low /include/fckeditor/editor/dialog/common (GET C=D;O=D)
236. Directory listing found Low /include/fckeditor/editor/css (GET C=S;O=A)
237. Directory listing found Low /include/fckeditor/editor/dialog/common/images (GET C=N;O=D)
238. Directory listing found Low /include/fckeditor/editor/dialog (GET C=S;O=D)
239. Directory listing found Low /include/fckeditor/editor/dialog/common/images (GET C=S;O=A)
240. Directory listing found Low /include/fckeditor/editor/dialog/common/images (GET C=D;O=A)
241. Directory listing found Low /include/fckeditor/editor/dialog/common/images (GET C=N;O=A)
242. Directory listing found Low /include/fckeditor/editor/dialog/common/images (GET C=M;O=D)
243. Directory listing found Low /include/fckeditor/editor/dialog/common/images (GET C=S;O=D)
244. Directory listing found Low /include/fckeditor/editor/dialog/common/images (GET C=D;O=D)
245. Directory listing found Low /include/fckeditor/editor/dialog/fck_about
246. Directory listing found Low /include/fckeditor/editor/dialog/fck_about (GET C=N;O=D)
247. Directory listing found Low /include/fckeditor/editor/dialog/common/images
248. Directory listing found Low /include/fckeditor/editor/css/behaviors (GET C=S;O=D)
249. Directory listing found Low /include/fckeditor/editor/css (GET C=M;O=D)
250. Directory listing found Low /include/fckeditor/editor/css (GET C=S;O=D)
251. Directory listing found Low /include/fckeditor/editor/css (GET C=D;O=D)
252. Directory listing found Low /include/fckeditor/editor/css/behaviors
253. Directory listing found Low /include/fckeditor/editor/css/behaviors (GET C=N;O=D)
254. Directory listing found Low /include/fckeditor/editor/css/behaviors (GET C=M;O=A)
255. Directory listing found Low /include/fckeditor/editor/css/behaviors (GET C=S;O=A)
256. Directory listing found Low /include/fckeditor/editor/css/behaviors (GET C=D;O=A)
257. Directory listing found Low /include/fckeditor/editor/dialog/common
258. Directory listing found Low /include/fckeditor/editor/css/behaviors (GET C=M;O=D)
259. Directory listing found Low /include/fckeditor/editor/dialog (GET C=D;O=D)
260. Directory listing found Low /include/fckeditor/editor/css/behaviors (GET C=D;O=D)
261. Directory listing found Low /include/fckeditor/editor/dialog
262. Directory listing found Low /include/fckeditor/editor/dialog (GET C=N;O=D)
263. Directory listing found Low /include/fckeditor/editor/dialog (GET C=M;O=A)
264. Directory listing found Low /include/fckeditor/editor/dialog (GET C=S;O=A)
265. Directory listing found Low /include/fckeditor/editor/dialog (GET C=D;O=A)
266. Directory listing found Low /include/fckeditor/editor/dialog (GET C=N;O=A)
267. Directory listing found Low /include/fckeditor/editor/dialog (GET C=M;O=D)
268. Directory listing found Low /include/fckeditor/editor/_source (GET C=N;O=A)
269. Directory listing found Low /include/fckeditor/editor/css/behaviors (GET C=N;O=A)
270. Directory listing found Low /include/ListView (GET C=S;O=D)
271. Directory listing found Low /include/Ajax (GET C=M;O=D)
272. Directory listing found Low /include/Ajax (GET C=S;O=D)
273. Directory listing found Low /include/Ajax (GET C=D;O=D)
274. Directory listing found Low /include/ListView
275. Directory listing found Low /include/ListView (GET C=N;O=D)
276. Directory listing found Low /include/ListView (GET C=M;O=A)
277. Directory listing found Low /include/ListView (GET C=S;O=A)
278. Directory listing found Low /include/ListView (GET C=D;O=A)
279. Directory listing found Low /include/fckeditor/editor/_source (GET C=S;O=D)
280. Directory listing found Low /include/ListView (GET C=M;O=D)
281. Directory listing found Low /include/Ajax (GET C=S;O=A)
282. Directory listing found Low /include/ListView (GET C=D;O=D)
283. Directory listing found Low /include/clock
284. Directory listing found Low /include/clock (GET C=N;O=D)
285. Directory listing found Low /include/clock (GET C=M;O=A)
286. Directory listing found Low /include/clock (GET C=S;O=A)
287. Directory listing found Low /include/clock (GET C=D;O=A)
288. Directory listing found Low /include/clock (GET C=N;O=A)
289. Directory listing found Low /include/clock (GET C=M;O=D)
290. Directory listing found Low /include/ListView (GET C=N;O=A)
291. Directory listing found Low /include/calculator (GET C=S;O=A)
292. Directory listing found Low /include/scriptaculous (GET C=N;O=D)
293. Directory listing found Low /include/scriptaculous (GET C=M;O=A)
294. Directory listing found Low /include/scriptaculous (GET C=S;O=A)
295. User credentials are sent in clear text Low /
296. Directory listing found Low /include/scriptaculous (GET C=N;O=A)
297. Directory listing found Low /include/scriptaculous (GET C=S;O=D)
298. Directory listing found Low /include/scriptaculous (GET C=D;O=D)
299. Directory listing found Low /include/calculator
300. Directory listing found Low /include/Ajax (GET C=N;O=A)
301. Directory listing found Low /include/calculator (GET C=M;O=A)
302. Directory listing found Low /include/Ajax (GET C=D;O=A)
303. Directory listing found Low /include/calculator (GET C=D;O=A)
304. Directory listing found Low /include/calculator (GET C=N;O=A)
305. Directory listing found Low /include/calculator (GET C=M;O=D)
306. Directory listing found Low /include/calculator (GET C=S;O=D)
307. Directory listing found Low /include/calculator (GET C=D;O=D)
308. Directory listing found Low /include/Ajax
309. Directory listing found Low /include/Ajax (GET C=N;O=D)
310. Directory listing found Low /include/Ajax (GET C=M;O=A)
311. Directory listing found Low /include/database
312. Directory listing found Low /include/calculator (GET C=N;O=D)
313. Directory listing found Low /include/fckeditor/editor (GET C=N;O=A)
314. Directory listing found Low /include/clock (GET C=S;O=D)
315. Directory listing found Low /include/fckeditor (GET C=N;O=A)
316. Directory listing found Low /include/fckeditor (GET C=M;O=D)
317. Directory listing found Low /include/fckeditor (GET C=S;O=D)
318. Directory listing found Low /include/fckeditor (GET C=D;O=D)
319. Directory listing found Low /include/fckeditor/editor
320. Directory listing found Low /include/fckeditor/editor (GET C=N;O=D)
321. Directory listing found Low /include/fckeditor/editor (GET C=M;O=A)
322. Directory listing found Low /include/fckeditor (GET C=S;O=A)
323. Directory listing found Low /include/fckeditor/editor (GET C=D;O=A)
324. Directory listing found Low /include/fckeditor (GET C=M;O=A)
325. Directory listing found Low /include/fckeditor/editor (GET C=M;O=D)
326. Directory listing found Low /include/fckeditor/editor (GET C=S;O=D)
327. Directory listing found Low /include/fckeditor/editor (GET C=D;O=D)
328. Directory listing found Low /include/fckeditor/editor/_source
329. Directory listing found Low /include/fckeditor/editor/_source (GET C=N;O=D)
330. Directory listing found Low /include/fckeditor/editor/_source (GET C=M;O=A)
331. Directory listing found Low /include/fckeditor/editor/_source (GET C=S;O=A)
332. Directory listing found Low /include/fckeditor/editor/_source (GET C=D;O=A)
333. Directory listing found Low /include/scriptaculous
334. Directory listing found Low /include/fckeditor/editor (GET C=S;O=A)
335. Directory listing found Low /include/db_backup (GET C=N;O=D)
336. Directory listing found Low /include/fckeditor/editor/_source (GET C=D;O=D)
337. Directory listing found Low /include/database (GET C=N;O=D)
338. Directory listing found Low /include/database (GET C=M;O=A)
339. Directory listing found Low /include/database (GET C=S;O=A)
340. Directory listing found Low /include/database (GET C=D;O=A)
341. Directory listing found Low /include/database (GET C=N;O=A)
342. Directory listing found Low /include/database (GET C=M;O=D)
343. Directory listing found Low /include/database (GET C=D;O=D)
344. Directory listing found Low /include/fckeditor (GET C=D;O=A)
345. Directory listing found Low /include/db_backup
346. Directory listing found Low /include/clock (GET C=D;O=D)
347. Directory listing found Low /include/db_backup (GET C=M;O=A)
348. Directory listing found Low /include/db_backup (GET C=S;O=A)
349. Directory listing found Low /include/db_backup (GET C=D;O=A)
350. Directory listing found Low /include/db_backup (GET C=N;O=A)
351. Directory listing found Low /include/db_backup (GET C=M;O=D)
352. Directory listing found Low /include/db_backup (GET C=D;O=D)
353. Directory listing found Low /include/db_backup (GET C=S;O=D)
354. Directory listing found Low /include/fckeditor
355. Directory listing found Low /include/fckeditor (GET C=N;O=D)
356. Directory listing found Low /include/database (GET C=S;O=D)

 1.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/aspx/connector.aspx
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to connector.aspx.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/aspx/connector.aspx HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=connector.aspx;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:40 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354026-3bf-d8618180"
Accept-Ranges: bytes
Content-Length: 959
Connection: close
Content-Type: text/plain

 2.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/io.asp
DetailsThe Cookie variable PHPSESSID has been set to io.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/io.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=io.asp;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:23 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354010-941-d8618180"
Accept-Ranges: bytes
Content-Length: 2369
Connection: close
Content-Type: text/plain

 3.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/io.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to io.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/io.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=io.asp;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:23 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354010-941-d8618180"
Accept-Ranges: bytes
Content-Length: 2369
Connection: close
Content-Type: text/plain

 4.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/io.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to io.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/io.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=io.asp
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:23 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354010-941-d8618180"
Accept-Ranges: bytes
Content-Length: 2369
Connection: close
Content-Type: text/plain

 5.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/util.asp
DetailsThe Cookie variable PHPSESSID has been set to util.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/util.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=util.asp;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:29 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354011-51c-d8618180"
Accept-Ranges: bytes
Content-Length: 1308
Connection: close
Content-Type: text/plain

 6.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/util.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to util.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/util.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=util.asp;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:29 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354011-51c-d8618180"
Accept-Ranges: bytes
Content-Length: 1308
Connection: close
Content-Type: text/plain

 7.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/util.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to util.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/util.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=util.asp;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:29 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354011-51c-d8618180"
Accept-Ranges: bytes
Content-Length: 1308
Connection: close
Content-Type: text/plain

 8.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/basexml.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to basexml.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/basexml.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=basexml.asp
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:57:54 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354013-6c8-d8618180"
Accept-Ranges: bytes
Content-Length: 1736
Connection: close
Content-Type: text/plain

 9.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/aspx/connector.aspx
DetailsThe Cookie variable PHPSESSID has been set to connector.aspx.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/aspx/connector.aspx HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=connector.aspx;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:40 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354026-3bf-d8618180"
Accept-Ranges: bytes
Content-Length: 959
Connection: close
Content-Type: text/plain

 10.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp
DetailsThe Cookie variable PHPSESSID has been set to connector.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=connector.asp;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:15 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "135400f-cf3-d8618180"
Accept-Ranges: bytes
Content-Length: 3315
Connection: close
Content-Type: text/plain

 11.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/aspx/connector.aspx
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to connector.aspx.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/aspx/connector.aspx HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=connector.aspx;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:40 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354026-3bf-d8618180"
Accept-Ranges: bytes
Content-Length: 959
Connection: close
Content-Type: text/plain

 12.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/aspx/connector.aspx
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to connector.aspx.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/aspx/connector.aspx HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=connector.aspx
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:40 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354026-3bf-d8618180"
Accept-Ranges: bytes
Content-Length: 959
Connection: close
Content-Type: text/plain

 13.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/perl/connector.cgi
DetailsThe Cookie variable PHPSESSID has been set to connector.cgi.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/perl/connector.cgi HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=connector.cgi;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:59:20 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "135401e-de9-d8618180"
Accept-Ranges: bytes
Content-Length: 3561
Connection: close
Content-Type: text/plain

 14.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/perl/connector.cgi
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to connector.cgi.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/perl/connector.cgi HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=connector.cgi;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:59:20 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "135401e-de9-d8618180"
Accept-Ranges: bytes
Content-Length: 3561
Connection: close
Content-Type: text/plain

 15.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/perl/connector.cgi
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to connector.cgi.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/perl/connector.cgi HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=connector.cgi;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:59:20 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "135401e-de9-d8618180"
Accept-Ranges: bytes
Content-Length: 3561
Connection: close
Content-Type: text/plain

 16.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/perl/connector.cgi
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to connector.cgi.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/perl/connector.cgi HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=connector.cgi
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:59:20 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "135401e-de9-d8618180"
Accept-Ranges: bytes
Content-Length: 3561
Connection: close
Content-Type: text/plain

 17.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/util.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to util.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/util.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=util.asp
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:29 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354011-51c-d8618180"
Accept-Ranges: bytes
Content-Length: 1308
Connection: close
Content-Type: text/plain

 18.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/config.asp
DetailsThe Cookie variable PHPSESSID has been set to config.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/config.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=config.asp;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:10 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354015-5ec-d8618180"
Accept-Ranges: bytes
Content-Length: 1516
Connection: close
Content-Type: text/plain

 19.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/class_upload.asp
DetailsThe Cookie variable PHPSESSID has been set to class_upload.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/class_upload.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=class_upload.asp;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:57:58 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354012-18bc-d8618180"
Accept-Ranges: bytes
Content-Length: 6332
Connection: close
Content-Type: text/plain

 20.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/class_upload.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to class_upload.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/class_upload.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=class_upload.asp;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:57:59 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354012-18bc-d8618180"
Accept-Ranges: bytes
Content-Length: 6332
Connection: close
Content-Type: text/plain

 21.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/class_upload.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to class_upload.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/class_upload.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=class_upload.asp;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:57:59 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354012-18bc-d8618180"
Accept-Ranges: bytes
Content-Length: 6332
Connection: close
Content-Type: text/plain

 22.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/class_upload.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to class_upload.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/class_upload.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=class_upload.asp
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:57:59 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354012-18bc-d8618180"
Accept-Ranges: bytes
Content-Length: 6332
Connection: close
Content-Type: text/plain

 23.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/commands.asp
DetailsThe Cookie variable PHPSESSID has been set to commands.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/commands.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=commands.asp;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:04 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354014-13dd-d8618180"
Accept-Ranges: bytes
Content-Length: 5085
Connection: close
Content-Type: text/plain

 24.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/commands.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to commands.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/commands.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=commands.asp;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:04 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354014-13dd-d8618180"
Accept-Ranges: bytes
Content-Length: 5085
Connection: close
Content-Type: text/plain

 25.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to connector.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=connector.asp;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:15 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "135400f-cf3-d8618180"
Accept-Ranges: bytes
Content-Length: 3315
Connection: close
Content-Type: text/plain

 26.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/commands.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to commands.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/commands.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=commands.asp
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:04 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354014-13dd-d8618180"
Accept-Ranges: bytes
Content-Length: 5085
Connection: close
Content-Type: text/plain

 27.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to connector.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=connector.asp;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:15 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "135400f-cf3-d8618180"
Accept-Ranges: bytes
Content-Length: 3315
Connection: close
Content-Type: text/plain

 28.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/config.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to config.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/config.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=config.asp;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:10 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354015-5ec-d8618180"
Accept-Ranges: bytes
Content-Length: 1516
Connection: close
Content-Type: text/plain

 29.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/config.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to config.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/config.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=config.asp;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:10 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354015-5ec-d8618180"
Accept-Ranges: bytes
Content-Length: 1516
Connection: close
Content-Type: text/plain

 30.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/config.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to config.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/config.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=config.asp
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:10 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354015-5ec-d8618180"
Accept-Ranges: bytes
Content-Length: 1516
Connection: close
Content-Type: text/plain

 31.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp
DetailsThe GET variable Command has been set to connector.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp?Command=connector.asp&Type=File&CurrentFolder=%2F HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:15 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "135400f-cf3-d8618180"
Accept-Ranges: bytes
Content-Length: 3315
Connection: close
Content-Type: text/plain

 32.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp
DetailsThe GET variable Type has been set to connector.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp?Command=FileUpload&Type=connector.asp&CurrentFolder=%2F HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:15 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "135400f-cf3-d8618180"
Accept-Ranges: bytes
Content-Length: 3315
Connection: close
Content-Type: text/plain

 33.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp
DetailsThe GET variable CurrentFolder has been set to connector.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp?Command=FileUpload&Type=File&CurrentFolder=connector.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:15 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "135400f-cf3-d8618180"
Accept-Ranges: bytes
Content-Length: 3315
Connection: close
Content-Type: text/plain

 34.  Script source code disclosure

Severity High
Affects /include/fckeditor/fckconfig.js
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to fckconfig.js.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/fckconfig.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=fckconfig.js;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:13:26 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "c7802d-22cc-d8618180"
Accept-Ranges: bytes
Content-Length: 8908
Connection: close
Content-Type: application/x-javascript

 35.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/commands.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to commands.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/commands.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=commands.asp;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:04 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354014-13dd-d8618180"
Accept-Ranges: bytes
Content-Length: 5085
Connection: close
Content-Type: text/plain

 36.  Script source code disclosure

Severity High
Affects /include/prototype-1.4.0/src/prototype.js
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to prototype.js.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/prototype-1.4.0/src/prototype.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=prototype.js;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:23:06 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "e0003e-186-d8618180"
Accept-Ranges: bytes
Content-Length: 390
Connection: close
Content-Type: application/x-javascript

 37.  Script source code disclosure

Severity High
Affects /include/fckeditor/fckconfig.js
DetailsThe Cookie variable PHPSESSID has been set to fckconfig.js.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/fckconfig.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=fckconfig.js;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:13:26 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "c7802d-22cc-d8618180"
Accept-Ranges: bytes
Content-Length: 8908
Connection: close
Content-Type: application/x-javascript

 38.  Script source code disclosure

Severity High
Affects /include/magpierss/rss_parse.inc
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to rss_parse.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/rss_parse.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=rss_parse.inc;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:31 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "13dc035-4cb8-d8618180"
Accept-Ranges: bytes
Content-Length: 19640
Connection: close
Content-Type: text/plain

 39.  Script source code disclosure

Severity High
Affects /include/magpierss/rss_parse.inc
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to rss_parse.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/rss_parse.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=rss_parse.inc;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:31 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "13dc035-4cb8-d8618180"
Accept-Ranges: bytes
Content-Length: 19640
Connection: close
Content-Type: text/plain

 40.  Script source code disclosure

Severity High
Affects /include/magpierss/rss_parse.inc
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to rss_parse.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/rss_parse.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=rss_parse.inc
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:31 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "13dc035-4cb8-d8618180"
Accept-Ranges: bytes
Content-Length: 19640
Connection: close
Content-Type: text/plain

 41.  Script source code disclosure

Severity High
Affects /include/magpierss/rss_utils.inc
DetailsThe Cookie variable PHPSESSID has been set to rss_utils.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/rss_utils.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=rss_utils.inc;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:44 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "13dc036-808-d8618180"
Accept-Ranges: bytes
Content-Length: 2056
Connection: close
Content-Type: text/plain

 42.  Script source code disclosure

Severity High
Affects /include/magpierss/rss_utils.inc
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to rss_utils.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/rss_utils.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=rss_utils.inc;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:44 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "13dc036-808-d8618180"
Accept-Ranges: bytes
Content-Length: 2056
Connection: close
Content-Type: text/plain

 43.  Script source code disclosure

Severity High
Affects /include/magpierss/rss_fetch.inc
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to rss_fetch.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/rss_fetch.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=rss_fetch.inc
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:20 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "13dc034-3ad3-d8618180"
Accept-Ranges: bytes
Content-Length: 15059
Connection: close
Content-Type: text/plain

 44.  Script source code disclosure

Severity High
Affects /include/magpierss/rss_utils.inc
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to rss_utils.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/rss_utils.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=rss_utils.inc
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:44 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "13dc036-808-d8618180"
Accept-Ranges: bytes
Content-Length: 2056
Connection: close
Content-Type: text/plain

 45.  Script source code disclosure

Severity High
Affects /include/magpierss/rss_fetch.inc
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to rss_fetch.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/rss_fetch.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=rss_fetch.inc;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:20 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "13dc034-3ad3-d8618180"
Accept-Ranges: bytes
Content-Length: 15059
Connection: close
Content-Type: text/plain

 46.  Script source code disclosure

Severity High
Affects /include/prototype-1.4.0/src/prototype.js
DetailsThe Cookie variable PHPSESSID has been set to prototype.js.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/prototype-1.4.0/src/prototype.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=prototype.js;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:23:06 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "e0003e-186-d8618180"
Accept-Ranges: bytes
Content-Length: 390
Connection: close
Content-Type: application/x-javascript

 47.  Script source code disclosure

Severity High
Affects /include/prototype-1.4.0/src/prototype.js
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to prototype.js.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/prototype-1.4.0/src/prototype.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=prototype.js;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:23:06 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "e0003e-186-d8618180"
Accept-Ranges: bytes
Content-Length: 390
Connection: close
Content-Type: application/x-javascript

 48.  Script source code disclosure

Severity High
Affects /include/prototype-1.4.0/src/prototype.js
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to prototype.js.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/prototype-1.4.0/src/prototype.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=prototype.js
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:23:06 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "e0003e-186-d8618180"
Accept-Ranges: bytes
Content-Length: 390
Connection: close
Content-Type: application/x-javascript

 49.  Script source code disclosure

Severity High
Affects /themes/bluelagoon/images/Thumbs.db
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to Thumbs.db.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /themes/bluelagoon/images/Thumbs.db HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=Thumbs.db;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:27:07 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "2640f0-77800-d8618180"
Accept-Ranges: bytes
Content-Length: 489472
Connection: close
Content-Type: text/plain

 50.  Script source code disclosure

Severity High
Affects /themes/bluelagoon/images/Thumbs.db
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to Thumbs.db.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /themes/bluelagoon/images/Thumbs.db HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=Thumbs.db;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:27:09 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "2640f0-77800-d8618180"
Accept-Ranges: bytes
Content-Length: 489472
Connection: close
Content-Type: text/plain

 51.  Script source code disclosure

Severity High
Affects /themes/bluelagoon/images/Thumbs.db
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to Thumbs.db.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /themes/bluelagoon/images/Thumbs.db HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=Thumbs.db
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:27:09 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "2640f0-77800-d8618180"
Accept-Ranges: bytes
Content-Length: 489472
Connection: close
Content-Type: text/plain

 52.  Script source code disclosure

Severity High
Affects /themes/bluelagoon/images/Thumbs.db
DetailsThe Cookie variable PHPSESSID has been set to Thumbs.db.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /themes/bluelagoon/images/Thumbs.db HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=Thumbs.db;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:27:10 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "2640f0-77800-d8618180"
Accept-Ranges: bytes
Content-Length: 489472
Connection: close
Content-Type: text/plain

 53.  Script source code disclosure

Severity High
Affects /include/magpierss/rss_utils.inc
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to rss_utils.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/rss_utils.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=rss_utils.inc;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:44 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "13dc036-808-d8618180"
Accept-Ranges: bytes
Content-Length: 2056
Connection: close
Content-Type: text/plain

 54.  Script source code disclosure

Severity High
Affects /include/magpierss/extlib/Snoopy.class.inc
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to Snoopy.class.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/extlib/Snoopy.class.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=Snoopy.class.inc;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:00 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "b20022-6d3c-d8618180"
Accept-Ranges: bytes
Content-Length: 27964
Connection: close
Content-Type: application/x-java-vm

 55.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to connector.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=connector.asp
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:15 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "135400f-cf3-d8618180"
Accept-Ranges: bytes
Content-Length: 3315
Connection: close
Content-Type: text/plain

 56.  Script source code disclosure

Severity High
Affects /include/fckeditor/fckconfig.js
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to fckconfig.js.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/fckconfig.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=fckconfig.js
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:13:26 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "c7802d-22cc-d8618180"
Accept-Ranges: bytes
Content-Length: 8908
Connection: close
Content-Type: application/x-javascript

 57.  Script source code disclosure

Severity High
Affects /include/install/images/Thumbs.db
DetailsThe Cookie variable PHPSESSID has been set to Thumbs.db.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/install/images/Thumbs.db HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=Thumbs.db;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:16:09 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "103c02e-13a00-d8618180"
Accept-Ranges: bytes
Content-Length: 80384
Connection: close
Content-Type: text/plain

 58.  Script source code disclosure

Severity High
Affects /include/install/images/Thumbs.db
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to Thumbs.db.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/install/images/Thumbs.db HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=Thumbs.db
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:16:09 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "103c02e-13a00-d8618180"
Accept-Ranges: bytes
Content-Length: 80384
Connection: close
Content-Type: text/plain

 59.  Script source code disclosure

Severity High
Affects /include/install/images/Thumbs.db
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to Thumbs.db.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/install/images/Thumbs.db HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=Thumbs.db;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:16:09 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "103c02e-13a00-d8618180"
Accept-Ranges: bytes
Content-Length: 80384
Connection: close
Content-Type: text/plain

 60.  Script source code disclosure

Severity High
Affects /include/install/images/Thumbs.db
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to Thumbs.db.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/install/images/Thumbs.db HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=Thumbs.db;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:16:09 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "103c02e-13a00-d8618180"
Accept-Ranges: bytes
Content-Length: 80384
Connection: close
Content-Type: text/plain

 61.  Script source code disclosure

Severity High
Affects /include/magpierss/rss_parse.inc
DetailsThe Cookie variable PHPSESSID has been set to rss_parse.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/rss_parse.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=rss_parse.inc;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:31 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "13dc035-4cb8-d8618180"
Accept-Ranges: bytes
Content-Length: 19640
Connection: close
Content-Type: text/plain

 62.  Script source code disclosure

Severity High
Affects /include/magpierss/extlib/Snoopy.class.inc
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to Snoopy.class.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/extlib/Snoopy.class.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=Snoopy.class.inc;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:00 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "b20022-6d3c-d8618180"
Accept-Ranges: bytes
Content-Length: 27964
Connection: close
Content-Type: application/x-java-vm

 63.  Script source code disclosure

Severity High
Affects /include/fckeditor/fckconfig.js
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to fckconfig.js.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/fckconfig.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=fckconfig.js;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:13:26 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "c7802d-22cc-d8618180"
Accept-Ranges: bytes
Content-Length: 8908
Connection: close
Content-Type: application/x-javascript

 64.  Script source code disclosure

Severity High
Affects /include/magpierss/extlib/Snoopy.class.inc
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to Snoopy.class.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/extlib/Snoopy.class.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=Snoopy.class.inc
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:00 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "b20022-6d3c-d8618180"
Accept-Ranges: bytes
Content-Length: 27964
Connection: close
Content-Type: application/x-java-vm

 65.  Script source code disclosure

Severity High
Affects /include/magpierss/rss_cache.inc
DetailsThe Cookie variable PHPSESSID has been set to rss_cache.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/rss_cache.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=rss_cache.inc;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:14 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "13dc033-18e8-d8618180"
Accept-Ranges: bytes
Content-Length: 6376
Connection: close
Content-Type: text/plain

 66.  Script source code disclosure

Severity High
Affects /include/magpierss/rss_cache.inc
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to rss_cache.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/rss_cache.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=rss_cache.inc;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:14 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "13dc033-18e8-d8618180"
Accept-Ranges: bytes
Content-Length: 6376
Connection: close
Content-Type: text/plain

 67.  Script source code disclosure

Severity High
Affects /include/magpierss/rss_cache.inc
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to rss_cache.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/rss_cache.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=rss_cache.inc;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:14 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "13dc033-18e8-d8618180"
Accept-Ranges: bytes
Content-Length: 6376
Connection: close
Content-Type: text/plain

 68.  Script source code disclosure

Severity High
Affects /include/magpierss/rss_cache.inc
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to rss_cache.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/rss_cache.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=rss_cache.inc
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:14 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "13dc033-18e8-d8618180"
Accept-Ranges: bytes
Content-Length: 6376
Connection: close
Content-Type: text/plain

 69.  Script source code disclosure

Severity High
Affects /include/magpierss/rss_fetch.inc
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to rss_fetch.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/rss_fetch.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=rss_fetch.inc;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:20 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "13dc034-3ad3-d8618180"
Accept-Ranges: bytes
Content-Length: 15059
Connection: close
Content-Type: text/plain

 70.  Script source code disclosure

Severity High
Affects /include/magpierss/rss_fetch.inc
DetailsThe Cookie variable PHPSESSID has been set to rss_fetch.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/rss_fetch.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=rss_fetch.inc;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:20 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "13dc034-3ad3-d8618180"
Accept-Ranges: bytes
Content-Length: 15059
Connection: close
Content-Type: text/plain

 71.  Script source code disclosure

Severity High
Affects /include/magpierss/extlib/Snoopy.class.inc
DetailsThe Cookie variable PHPSESSID has been set to Snoopy.class.inc.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/magpierss/extlib/Snoopy.class.inc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=Snoopy.class.inc;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 14:17:00 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "b20022-6d3c-d8618180"
Accept-Ranges: bytes
Content-Length: 27964
Connection: close
Content-Type: application/x-java-vm

 72.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/basexml.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to basexml.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/basexml.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=basexml.asp;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:57:54 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354013-6c8-d8618180"
Accept-Ranges: bytes
Content-Length: 1736
Connection: close
Content-Type: text/plain

 73.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/basexml.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to basexml.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/basexml.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=basexml.asp;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:57:54 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354013-6c8-d8618180"
Accept-Ranges: bytes
Content-Length: 1736
Connection: close
Content-Type: text/plain

 74.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/basexml.asp
DetailsThe Cookie variable PHPSESSID has been set to basexml.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/basexml.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=basexml.asp;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:57:54 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354013-6c8-d8618180"
Accept-Ranges: bytes
Content-Length: 1736
Connection: close
Content-Type: text/plain

 75.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.pl
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to spellchecker.pl.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.pl HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=spellchecker.pl;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:54:34 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1360011-1227-d8618180"
Accept-Ranges: bytes
Content-Length: 4647
Connection: close
Content-Type: text/x-perl

 76.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.pl
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger has been set to spellchecker.pl.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.pl HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=spellchecker.pl;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:54:34 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1360011-1227-d8618180"
Accept-Ranges: bytes
Content-Length: 4647
Connection: close
Content-Type: text/x-perl

 77.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.pl
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger=1; ck_login_theme_vtiger=bluelagoon; ck_login_language_vtiger has been set to spellchecker.pl.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.pl HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=spellchecker.pl
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:54:34 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1360011-1227-d8618180"
Accept-Ranges: bytes
Content-Length: 4647
Connection: close
Content-Type: text/x-perl

 78.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.pl
DetailsThe Cookie variable PHPSESSID has been set to spellchecker.pl.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.pl HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=spellchecker.pl;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:54:34 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1360011-1227-d8618180"
Accept-Ranges: bytes
Content-Length: 4647
Connection: close
Content-Type: text/x-perl

 79.  Script source code disclosure

Severity High
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/io.asp
DetailsThe Cookie variable PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; ck_login_id_vtiger has been set to io.asp.
TypeValidation
DescriptionIt is possible to read the source code of this script by using script filename as a parameter. It seems that this script includes a file which name is determined using user-supplied data. This data is not properly validated before being passed to the include function.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to launch further attacks.
RecommendationAnalyse the source code of this script and solve the problem.
Reported by moduleParameter manipulation
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/io.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=io.asp;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 13:58:23 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1354010-941-d8618180"
Accept-Ranges: bytes
Content-Length: 2369
Connection: close
Content-Type: text/plain

 80.  Source code disclosure

Severity Medium
Affects /include/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.pl
DetailsWe have found #!/usr/bin/perl
TypeValidation
DescriptionLooks like the source code for this script is available. This check is using pattern matching to determine if server side tags are found in the file. In some cases this may generate false positives.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to conduct further attacks.
RecommendationRemove this file from your website or change permissions in order to remove access.
Reported by moduleText search
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.pl HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:46 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: "1360011-1227-d8618180"
Accept-Ranges: bytes
Content-Length: 4647
Connection: close
Content-Type: text/x-perl

 81.  PHPSESSID session fixation

Severity Medium
Affects /
DetailsNo details are available.
TypeValidation
DescriptionThis script is vulnerable to PHPSESSID session fixation attacks.

By injecting a custom PHPSESSID is possible to alter the PHP session cookie. Attackers will normally manipulate cookie values to fraudulently authenticate themselves on a web site.
ImpactBy exploiting this vulnerability, an attacker may conduct a session fixation attack. In a session fixation attack, the attacker fixes the user's session ID before the user even logs into the target server, thereby eliminating the need to obtain the user's session ID afterwards.
RecommendationSet session.use_only_cookies = 1 from php.ini. This option enables administrators to make their users invulnerable to attacks which involve passing session ids in URLs; defaults to 0.
Reported by moduleDirectory checks
References
Session fixationhttp://www.acros.si/papers/session_fixation.pdf
Session Handling Functionshttp://www.php.net/session
OWASP PHP Top 5http://www.owasp.org/index.php/PHP_Top_5
Request
GET /?PHPSESSID=acunetixsessionfixation HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 15:13:08 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
X-Powered-By: PHP/4.3.10-16
Set-Cookie: PHPSESSID=acunetixsessionfixation; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 7402
Connection: close
Content-Type: text/html; charset=ISO-8859-1

 82.  Source code disclosure

Severity Medium
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/aspx/connector.aspx
DetailsWe have found <%@ Page language="c#" Inherits="FredCK.FCKeditorV2.FileBrowserConnector" AutoEventWireup="false" %>
TypeValidation
DescriptionLooks like the source code for this script is available. This check is using pattern matching to determine if server side tags are found in the file. In some cases this may generate false positives.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to conduct further attacks.
RecommendationRemove this file from your website or change permissions in order to remove access.
Reported by moduleText search
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/aspx/connector.aspx HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/filemanager/browser/default/connectors/aspx/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:50 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;1354026-3bf-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 959
Connection: close
Content-Type: text/plain

 83.  Source code disclosure

Severity Medium
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/util.asp
DetailsWe have found <% Function RemoveFromStart( sourceString, charToRemove ) Dim oRegex Set oRegex = New RegExp oRegex.Pattern = "^" & charToRemove & "+" RemoveFromStart = oRegex.Replace( sourceString, "" ) End Function Function RemoveFromEnd( sourceString, charToRemove ) Dim oRegex Set oRegex = New RegExp oRegex.Pattern = charToRemove & "+$" RemoveFromEnd = oRegex.Replace( sourceString, "" ) End Function Function ConvertToXmlAttribute( value ) ConvertToXmlAttribute = Replace( value, "&", "&amp;" ) End Function Function InArray( value, sourceArray ) Dim i For i = 0 to UBound( sourceArray ) If sourceArray(i) = value Then InArray = True Exit Function End If Next InArray = False End Function %>
TypeValidation
DescriptionLooks like the source code for this script is available. This check is using pattern matching to determine if server side tags are found in the file. In some cases this may generate false positives.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to conduct further attacks.
RecommendationRemove this file from your website or change permissions in order to remove access.
Reported by moduleText search
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/util.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/filemanager/browser/default/connectors/asp/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:49 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;1354011-51c-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 1308
Connection: close
Content-Type: text/plain

 84.  Source code disclosure

Severity Medium
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/io.asp
DetailsWe have found <% Function GetUrlFromPath( resourceType, folderPath ) If resourceType = "" Then GetUrlFromPath = RemoveFromEnd( sUserFilesPath, "/" ) & folderPath Else GetUrlFromPath = sUserFilesPath & resourceType & folderPath End If End Function Function RemoveExtension( fileName ) RemoveExtension = Left( fileName, InStrRev( fileName, "." ) - 1 ) End Function Function ServerMapFolder( resourceType, folderPath ) ' Get the resource type directory. Dim sResourceTypePath sResourceTypePath = sUserFilesDirectory & resourceType & "\" ' Ensure that the directory exists. CreateServerFolder sResourceTypePath ' Return the resource type directory combined with the required path. ServerMapFolder = sResourceTypePath & RemoveFromStart( folderPath, "/" ) End Function Sub CreateServerFolder( folderPath ) Dim oFSO Set oFSO = Server.CreateObject( "Scripting.FileSystemObject" ) Dim sParent sParent = oFSO.GetParentFolderName( folderPath ) ' Check if the parent exists, or create it. If ( NOT oFSO.FolderExists( sParent ) ) Then CreateServerFolder( sParent ) If ( oFSO.FolderExists( folderPath ) = False ) Then oFSO.CreateFolder( folderPath ) End If Set oFSO = Nothing End Sub Function IsAllowedExt( extension, resourceType ) Dim oRE Set oRE = New RegExp oRE.IgnoreCase = True oRE.Global = True Dim sAllowed, sDenied sAllowed = ConfigAllowedExtensions.Item( resourceType ) sDenied = ConfigDeniedExtensions.Item( resourceType ) IsAllowedExt = True If sDenied <> "" Then oRE.Pattern = sDenied IsAllowedExt = Not oRE.Test( extension ) End If If IsAllowedExt And sAllowed <> "" Then oRE.Pattern = sAllowed IsAllowedExt = oRE.Test( extension ) End If Set oRE = Nothing End Function %>
TypeValidation
DescriptionLooks like the source code for this script is available. This check is using pattern matching to determine if server side tags are found in the file. In some cases this may generate false positives.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to conduct further attacks.
RecommendationRemove this file from your website or change permissions in order to remove access.
Reported by moduleText search
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/io.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/filemanager/browser/default/connectors/asp/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:49 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;1354010-941-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 2369
Connection: close
Content-Type: text/plain

 85.  Source code disclosure

Severity Medium
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp
DetailsWe have found <%@ CodePage=65001 Language="VBScript"%>
TypeValidation
DescriptionLooks like the source code for this script is available. This check is using pattern matching to determine if server side tags are found in the file. In some cases this may generate false positives.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to conduct further attacks.
RecommendationRemove this file from your website or change permissions in order to remove access.
Reported by moduleText search
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/filemanager/browser/default/connectors/asp/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:49 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;135400f-cf3-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 3315
Connection: close
Content-Type: text/plain

 86.  Source code disclosure

Severity Medium
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/config.asp
DetailsWe have found <% ' SECURITY: You must explicitelly enable this "connector" (set it to "True"). Dim ConfigIsEnabled ConfigIsEnabled = False ' Path to user files relative to the document root. Dim ConfigUserFilesPath ConfigUserFilesPath = "/UserFiles/" Dim ConfigAllowedExtensions, ConfigDeniedExtensions Set ConfigAllowedExtensions = CreateObject( "Scripting.Dictionary" ) Set ConfigDeniedExtensions = CreateObject( "Scripting.Dictionary" ) ConfigAllowedExtensions.Add "File", "" ConfigDeniedExtensions.Add "File", "php|asp|aspx|ascx|jsp|cfm|cfc|pl|bat|exe|com|dll|vbs|js|reg" ConfigAllowedExtensions.Add "Image", "jpg|gif|jpeg|png|bmp" ConfigDeniedExtensions.Add "Image", "" ConfigAllowedExtensions.Add "Flash", "swf|fla" ConfigDeniedExtensions.Add "Flash", "" ConfigAllowedExtensions.Add "Media", "swf|fla|jpg|gif|jpeg|png|avi|mpg|mpeg|mp(1-4)|wma|wmv|wav|mid|midi|rmi|rm|ram|rmvb|mov|qt" ConfigDeniedExtensions.Add "Media", "" %>
TypeValidation
DescriptionLooks like the source code for this script is available. This check is using pattern matching to determine if server side tags are found in the file. In some cases this may generate false positives.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to conduct further attacks.
RecommendationRemove this file from your website or change permissions in order to remove access.
Reported by moduleText search
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/config.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/filemanager/browser/default/connectors/asp/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:49 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;1354015-5ec-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 1516
Connection: close
Content-Type: text/plain

 87.  Source code disclosure

Severity Medium
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/commands.asp
DetailsWe have found <% Sub GetFolders( resourceType, currentFolder ) ' Map the virtual path to the local server path. Dim sServerDir sServerDir = ServerMapFolder( resourceType, currentFolder ) ' Open the "Folders" node. Response.Write "<Folders>" Dim oFSO, oCurrentFolder, oFolders, oFolder Set oFSO = Server.CreateObject( "Scripting.FileSystemObject" ) Set oCurrentFolder = oFSO.GetFolder( sServerDir ) Set oFolders = oCurrentFolder.SubFolders For Each oFolder in oFolders Response.Write "<Folder name=""" & ConvertToXmlAttribute( oFolder.name ) & """ />" Next Set oFSO = Nothing ' Close the "Folders" node. Response.Write "</Folders>" End Sub Sub GetFoldersAndFiles( resourceType, currentFolder ) ' Map the virtual path to the local server path. Dim sServerDir sServerDir = ServerMapFolder( resourceType, currentFolder ) Dim oFSO, oCurrentFolder, oFolders, oFolder, oFiles, oFile Set oFSO = Server.CreateObject( "Scripting.FileSystemObject" ) Set oCurrentFolder = oFSO.GetFolder( sServerDir ) Set oFolders = oCurrentFolder.SubFolders Set oFiles = oCurrentFolder.Files ' Open the "Folders" node. Response.Write "<Folders>" For Each oFolder in oFolders Response.Write "<Folder name=""" & ConvertToXmlAttribute( oFolder.name ) & """ />" Next ' Close the "Folders" node. Response.Write "</Folders>" ' Open the "Files" node. Response.Write "<Files>" For Each oFile in oFiles Dim iFileSize iFileSize = Round( oFile.size / 1024 ) If ( iFileSize < 1 AND oFile.size <> 0 ) Then iFileSize = 1 Response.Write "<File name=""" & ConvertToXmlAttribute( oFile.name ) & """ size=""" & iFileSize & """ />" Next ' Close the "Files" node. Response.Write "</Files>" End Sub Sub CreateFolder( resourceType, currentFolder ) Dim sErrorNumber Dim sNewFolderName sNewFolderName = Request.QueryString( "NewFolderName" ) If ( sNewFolderName = "" OR InStr( 1, sNewFolderName, ".." ) > 0 ) Then sErrorNumber = "102" Else ' Map the virtual path to the local server path of the current folder. Dim sServerDir sServerDir = ServerMapFolder( resourceType, currentFolder & "/" & sNewFolderName ) On Error Resume Next CreateServerFolder sServerDir Dim iErrNumber, sErrDescription iErrNumber = err.number sErrDescription = err.Description On Error Goto 0 Select Case iErrNumber Case 0 sErrorNumber = "0" Case 52 sErrorNumber = "102" ' Invalid Folder Name. Case 70 sErrorNumber = "103" ' Security Error. Case 76 sErrorNumber = "102" ' Path too long. Case Else sErrorNumber = "110" End Select End If ' Create the "Error" node. Response.Write "<Error number=""" & sErrorNumber & """ originalNumber=""" & iErrNumber & """ originalDescription=""" & ConvertToXmlAttribute( sErrDescription ) & """ />" End Sub Sub FileUpload( resourceType, currentFolder ) Dim oUploader Set oUploader = New NetRube_Upload oUploader.MaxSize = 0 oUploader.Allowed = ConfigAllowedExtensions.Item( resourceType ) oUploader.Denied = ConfigDeniedExtensions.Item( resourceType ) oUploader.GetData Dim sErrorNumber sErrorNumber = "0" Dim sFileName, sOriginalFileName, sExtension sFileName = "" If oUploader.ErrNum > 1 Then sErrorNumber = "202" Else ' Map the virtual path to the local server path. Dim sServerDir sServerDir = ServerMapFolder( resourceType, currentFolder ) Dim oFSO Set oFSO = Server.CreateObject( "Scripting.FileSystemObject" ) ' Get the uploaded file name. sFileName = oUploader.File( "NewFile" ).Name sExtension = oUploader.File( "NewFile" ).Ext sOriginalFileName = sFileName Dim iCounter iCounter = 0 Do While ( True ) Dim sFilePath sFilePath = sServerDir & sFileName If ( oFSO.FileExists( sFilePath ) ) Then iCounter = iCounter + 1 sFileName = RemoveExtension( sOriginalFileName ) & "(" & iCounter & ")." & sExtension sErrorNumber = "201" Else oUploader.SaveAs "NewFile", sFilePath If oUploader.ErrNum > 0 Then sErrorNumber = "202" Exit Do End If Loop End If Set oUploader = Nothing Response.Clear Response.Write "<script type=""text/javascript"">" Response.Write "window.parent.frames['frmUpload'].OnUploadCompleted(" & sErrorNumber & ",'" & Replace( sFileName, "'", "\'" ) & "') ;" Response.Write "</script>" Response.End End Sub %>
TypeValidation
DescriptionLooks like the source code for this script is available. This check is using pattern matching to determine if server side tags are found in the file. In some cases this may generate false positives.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to conduct further attacks.
RecommendationRemove this file from your website or change permissions in order to remove access.
Reported by moduleText search
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/commands.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/filemanager/browser/default/connectors/asp/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:49 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;1354014-13dd-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 5085
Connection: close
Content-Type: text/plain

 88.  Source code disclosure

Severity Medium
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/class_upload.asp
DetailsWe have found <% '********************************************** ' File: NetRube_Upload.asp ' Version: NetRube Upload Class Version 2.1 Build 20050228 ' Author: NetRube ' Email: NetRube@126.com ' Date: 02/28/2005 ' Comments: The code for the Upload. ' This can free usage, but please ' not to delete this copyright information. ' If you have a modification version, ' Please send out a duplicate to me. '********************************************** ' #########: NetRube_Upload.asp ' ######: NetRube Upload Class Version 2.1 Build 20050228 ' ######: NetRube(###############) ' ############: NetRube@126.com ' ######: 2005###02###28### ' ######: ############### ' ################################################################## ' ############################################# ' ######################## '********************************************** Class NetRube_Upload Public File, Form Private oSourceData Private nMaxSize, nErr, sAllowed, sDenied Private Sub Class_Initialize nErr = 0 nMaxSize = 1048576 Set File = Server.CreateObject("Scripting.Dictionary") File.CompareMode = 1 Set Form = Server.CreateObject("Scripting.Dictionary") Form.CompareMode = 1 Set oSourceData = Server.CreateObject("ADODB.Stream") oSourceData.Type = 1 oSourceData.Mode = 3 oSourceData.Open End Sub Private Sub Class_Terminate Form.RemoveAll Set Form = Nothing File.RemoveAll Set File = Nothing oSourceData.Close Set oSourceData = Nothing End Sub Public Property Get Version Version = "NetRube Upload Class Version 1.0 Build 20041218" End Property Public Property Get ErrNum ErrNum = nErr End Property Public Property Let MaxSize(nSize) nMaxSize = nSize End Property Public Property Let Allowed(sExt) sAllowed = sExt End Property Public Property Let Denied(sExt) sDenied = sExt End Property Public Sub GetData Dim aCType aCType = Split(Request.ServerVariables("HTTP_CONTENT_TYPE"), ";") If aCType(0) <> "multipart/form-data" Then nErr = 1 Exit Sub End If Dim nTotalSize nTotalSize = Request.TotalBytes If nTotalSize < 1 Then nErr = 2 Exit Sub End If If nMaxSize > 0 And nTotalSize > nMaxSize Then nErr = 3 Exit Sub End If oSourceData.Write Request.BinaryRead(nTotalSize) oSourceData.Position = 0 Dim oTotalData, oFormStream, sFormHeader, sFormName, bCrLf, nBoundLen, nFormStart, nFormEnd, nPosStart, nPosEnd, sBoundary oTotalData = oSourceData.Read bCrLf = ChrB(13) & ChrB(10) sBoundary = MidB(oTotalData, 1, InStrB(1, oTotalData, bCrLf) - 1) nBoundLen = LenB(sBoundary) + 2 nFormStart = nBoundLen Set oFormStream = Server.CreateObject("ADODB.Stream") Do While (nFormStart + 2) < nTotalSize nFormEnd = InStrB(nFormStart, oTotalData, bCrLf & bCrLf) + 3 With oFormStream .Type = 1 .Mode = 3 .Open oSourceData.Position = nFormStart oSourceData.CopyTo oFormStream, nFormEnd - nFormStart .Position = 0 .Type = 2 .CharSet = "UTF-8" sFormHeader = .ReadText .Close End With nFormStart = InStrB(nFormEnd, oTotalData, sBoundary) - 1 nPosStart = InStr(22, sFormHeader, " name=", 1) + 7 nPosEnd = InStr(nPosStart, sFormHeader, """") sFormName = Mid(sFormHeader, nPosStart, nPosEnd - nPosStart) If InStr(45, sFormHeader, " filename=", 1) > 0 Then Set File(sFormName) = New NetRube_FileInfo File(sFormName).FormName = sFormName File(sFormName).Start = nFormEnd File(sFormName).Size = nFormStart - nFormEnd - 2 nPosStart = InStr(nPosEnd, sFormHeader, " filename=", 1) + 11 nPosEnd = InStr(nPosStart, sFormHeader, """") File(sFormName).ClientPath = Mid(sFormHeader, nPosStart, nPosEnd - nPosStart) File(sFormName).Name = Mid(File(sFormName).ClientPath, InStrRev(File(sFormName).ClientPath, "\") + 1) File(sFormName).Ext = LCase(Mid(File(sFormName).Name, InStrRev(File(sFormName).Name, ".") + 1)) nPosStart = InStr(nPosEnd, sFormHeader, "Content-Type: ", 1) + 14 nPosEnd = InStr(nPosStart, sFormHeader, vbCr) File(sFormName).MIME = Mid(sFormHeader, nPosStart, nPosEnd - nPosStart) Else With oFormStream .Type = 1 .Mode = 3 .Open oSourceData.Position = nPosEnd oSourceData.CopyTo oFormStream, nFormStart - nFormEnd - 2 .Position = 0 .Type = 2 .CharSet = "UTF-8" Form(sFormName) = .ReadText .Close End With End If nFormStart = nFormStart + nBoundLen Loop oTotalData = "" Set oFormStream = Nothing End Sub Public Sub SaveAs(sItem, sFileName) If File(sItem).Size < 1 Then nErr = 2 Exit Sub End If If Not IsAllowed(File(sItem).Ext) Then nErr = 4 Exit Sub End If Dim oFileStream Set oFileStream = Server.CreateObject("ADODB.Stream") With oFileStream .Type = 1 .Mode = 3 .Open oSourceData.Position = File(sItem).Start oSourceData.CopyTo oFileStream, File(sItem).Size .Position = 0 .SaveToFile sFileName, 2 .Close End With Set oFileStream = Nothing End Sub Private Function IsAllowed(sExt) Dim oRE Set oRE = New RegExp oRE.IgnoreCase = True oRE.Global = True If sDenied = "" Then oRE.Pattern = sAllowed IsAllowed = (sAllowed = "") Or oRE.Test(sExt) Else oRE.Pattern = sDenied IsAllowed = Not oRE.Test(sExt) End If Set oRE = Nothing End Function End Class Class NetRube_FileInfo Dim FormName, ClientPath, Path, Name, Ext, Content, Size, MIME, Start End Class %>
TypeValidation
DescriptionLooks like the source code for this script is available. This check is using pattern matching to determine if server side tags are found in the file. In some cases this may generate false positives.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to conduct further attacks.
RecommendationRemove this file from your website or change permissions in order to remove access.
Reported by moduleText search
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/class_upload.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/filemanager/browser/default/connectors/asp/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:49 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;1354012-18bc-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 6332
Connection: close
Content-Type: text/plain

 89.  Apache 2.x version older than 2.0.55

Severity Medium
Affects Web Server
DetailsCurrent version is Apache/2.0.54
TypeConfiguration
Description
This alert has been generated using only banner information. It may be a false positive.

Multiple vulnerabilities have been found in this version of Apache. You should upgrade to the latest version of Apache.

Affected Apache versions (up to 2.0.55).
ImpactMultiple. Check references for details about every vulnerability.
RecommendationUpgrade Apache 2.x to the latest version.
Reported by moduleVersion check
References
CAN-2005-2088http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2088
CAN-2005-2700http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2700
CAN-2005-2491http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2491
CAN-2005-2728http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2728
CAN-2005-1268http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1268
Apache homepagehttp://httpd.apache.org
Apache HTTP Server 2.x announcementhttp://www.apache.org/dist/httpd/Announcement2.0.html
Request
Response

 90.  Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability

Severity Medium
Affects Web Server
DetailsCurrent version is Apache/2.0.54
TypeConfiguration
Description
This alert has been generated using only banner information. It may be a false positive.

Apache mod_rewrite is prone to an off-by-one buffer-overflow condition. The vulnerability arising in the mod_rewrite module's ldap scheme handling allows for potential memory corruption when an attacker exploits certain rewrite rules.

Affected Apache versions:
ImpactAn attacker may exploit this issue to trigger a denial-of-service condition. Reportedly, arbitrary code execution may be possible as well.
RecommendationUpgrade Apache to the latest version.
Reported by moduleVersion check
References
BID 19204http://www.securityfocus.com/bid/19204
Apache homepagehttp://httpd.apache.org
VU#395412http://www.kb.cert.org/vuls/id/395412
Request
Response

 91.  Source code disclosure

Severity Medium
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/basexml.asp
DetailsWe have found <% Sub SetXmlHeaders() ' Cleans the response buffer. Response.Clear() ' Prevent the browser from caching the result. Response.CacheControl = "no-cache" ' Set the response format. Response.CharSet = "UTF-8" Response.ContentType = "text/xml" End Sub Sub CreateXmlHeader( command, resourceType, currentFolder ) ' Create the XML document header. Response.Write "<?xml version=""1.0"" encoding=""utf-8"" ?>" ' Create the main "Connector" node. Response.Write "<Connector command=""" & command & """ resourceType=""" & resourceType & """>" ' Add the current folder node. Response.Write "<CurrentFolder path=""" & ConvertToXmlAttribute( currentFolder ) & """ url=""" & ConvertToXmlAttribute( GetUrlFromPath( resourceType, currentFolder) ) & """ />" End Sub Sub CreateXmlFooter() Response.Write "</Connector>" End Sub Sub SendError( number, text ) SetXmlHeaders ' Create the XML document header. Response.Write "<?xml version=""1.0"" encoding=""utf-8"" ?>" Response.Write "<Connector><Error number=""" & number & """ text=""" & Server.HTMLEncode( text ) & """ /></Connector>" Response.End End Sub %>
TypeValidation
DescriptionLooks like the source code for this script is available. This check is using pattern matching to determine if server side tags are found in the file. In some cases this may generate false positives.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to conduct further attacks.
RecommendationRemove this file from your website or change permissions in order to remove access.
Reported by moduleText search
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/basexml.asp HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/filemanager/browser/default/connectors/asp/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:49 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;1354013-6c8-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 1736
Connection: close
Content-Type: text/plain

 92.  Full path disclosure

Severity Medium
Affects /index.php
DetailsThe Cookie variable PHPSESSID has been set to '.
TypeValidation
DescriptionThis script is vulnerable to full path disclosure.

By injecting unexpected data into a parameter it's possible to generate an error that will reveal the full path of the script.
ImpactA remote user can determine the full path to the web root directory and other potentially sensitive information.
RecommendationYour script should properly sanitize user input.
Reported by moduleParameter manipulation
References
Request
GET /index.php HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=';ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:08:49 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
X-Powered-By: PHP/4.3.10-16
Connection: close
Content-Type: text/html; charset=ISO-8859-1

 93.  Source code disclosure

Severity Medium
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/perl/connector.cgi
DetailsWe have found #!/usr/bin/env perl ##### # FCKeditor - The text editor for internet # Copyright (C) 2003-2005 Frederico Caldeira Knabben # # Licensed under the terms of the GNU Lesser General Public License: # http://www.opensource.org/licenses/lgpl-license.php # # For further information visit: # http://www.fckeditor.net/ # # "Support Open Source software. What about a donation today?" # # File Name: connector.cgi # This is the File Manager Connector for Perl. # # File Authors: # Takashi Yamaguchi (jack@omakase.net) # Frederico Caldeira Knabben (fredck@fckeditor.net) ##### ## # ATTENTION: To enable this connector, look for the "SECURITY" comment in this file. ## ## START: Hack for Windows (Not important to understand the editor code... Perl specific). if(Windows_check()) { chdir(GetScriptPath($0)); } sub Windows_check { # IIS,PWS(NT/95) $www_server_os = $^O; # Win98 & NT(SP4) if($www_server_os eq "") { $www_server_os= $ENV{'OS'}; } # AnHTTPd/Omni/IIS if($ENV{'SERVER_SOFTWARE'} =~ /AnWeb|Omni|IIS\//i) { $www_server_os= 'win'; } # Win Apache if($ENV{'WINDIR'} ne "") { $www_server_os= 'win'; } if($www_server_os=~ /win/i) { return(1); } return(0); } sub GetScriptPath { local($path) = @_; if($path =~ /[\:\/\\]/) { $path =~ s/(.*?)[\/\\][^\/\\]+$/$1/; } else { $path = '.'; } $path; } ## END: Hack for IIS require 'util.pl'; require 'io.pl'; require 'basexml.pl'; require 'commands.pl'; require 'upload_fck.pl'; ## # SECURITY: REMOVE/COMMENT THE FOLLOWING LINE TO ENABLE THIS CONNECTOR. ## &SendError( 1, 'This connector is disabled. Please check the "editor/filemanager/browser/default/connectors/perl
TypeValidation
DescriptionLooks like the source code for this script is available. This check is using pattern matching to determine if server side tags are found in the file. In some cases this may generate false positives.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to conduct further attacks.
RecommendationRemove this file from your website or change permissions in order to remove access.
Reported by moduleText search
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/perl/connector.cgi HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/filemanager/browser/default/connectors/perl/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:50 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;135401e-de9-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 3561
Connection: close
Content-Type: text/plain

 94.  Source code disclosure

Severity Medium
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp (GET Command=FileUpload&Type=File&CurrentFolder=/)
DetailsWe have found <%@ CodePage=65001 Language="VBScript"%>
TypeValidation
DescriptionLooks like the source code for this script is available. This check is using pattern matching to determine if server side tags are found in the file. In some cases this may generate false positives.
ImpactAn attacker can gather sensitive information (database connection strings, application logic) by analysing the source code. This information can be used to conduct further attacks.
RecommendationRemove this file from your website or change permissions in order to remove access.
Reported by moduleText search
References
iMPERVA Source Code Disclosurehttp://www.imperva.com/application_defense_center/glossary/source_code_disclosure.html
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp?Command=FileUpload&amp;Type=File&amp;CurrentFolder=/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/filemanager/browser/default/connectors/test.html
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:03:03 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;135400f-cf3-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 3315
Connection: close
Content-Type: text/plain

 95.  Full path disclosure

Severity Medium
Affects /
DetailsThe Cookie variable PHPSESSID has been set to '.
TypeValidation
DescriptionThis script is vulnerable to full path disclosure.

By injecting unexpected data into a parameter it's possible to generate an error that will reveal the full path of the script.
ImpactA remote user can determine the full path to the web root directory and other potentially sensitive information.
RecommendationYour script should properly sanitize user input.
Reported by moduleParameter manipulation
References
Request
GET / HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=';ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:04:13 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
X-Powered-By: PHP/4.3.10-16
Connection: close
Content-Type: text/html; charset=ISO-8859-1

 96.  Possible sensitive directories

Severity Low
Affects /test/
DetailsNo details are available.
TypeValidation
DescriptionA possible sensitive directory has been found. This check looks for known sensitive directories like: backup directories, database dumps, administration pages, temporary directories. Each of those directories may help an attacker to learn more about his target.
ImpactThis directory may expose sensitive information that may help an malicious user to prepare more advanced attacks.
RecommendationRestrict access to this directory or remove it from the website.
Reported by moduleDirectory checks
References
Security Focus : Ten Steps to a Cleaner Web Root http://www.securityfocus.com/infocus/1318
Request
GET /test/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 15:12:46 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1174
Connection: close
Content-Type: text/html

 97.  Possible sensitive directories

Severity Low
Affects /modules/Webmails/tmp/
DetailsNo details are available.
TypeValidation
DescriptionA possible sensitive directory has been found. This check looks for known sensitive directories like: backup directories, database dumps, administration pages, temporary directories. Each of those directories may help an attacker to learn more about his target.
ImpactThis directory may expose sensitive information that may help an malicious user to prepare more advanced attacks.
RecommendationRestrict access to this directory or remove it from the website.
Reported by moduleDirectory checks
References
Security Focus : Ten Steps to a Cleaner Web Root http://www.securityfocus.com/infocus/1318
Request
GET /modules/Webmails/tmp/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 15:31:45 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 527
Connection: close
Content-Type: text/html

 98.  Possible sensitive directories

Severity Low
Affects /include/prototype-1.4.0/test/
DetailsNo details are available.
TypeValidation
DescriptionA possible sensitive directory has been found. This check looks for known sensitive directories like: backup directories, database dumps, administration pages, temporary directories. Each of those directories may help an attacker to learn more about his target.
ImpactThis directory may expose sensitive information that may help an malicious user to prepare more advanced attacks.
RecommendationRestrict access to this directory or remove it from the website.
Reported by moduleDirectory checks
References
Security Focus : Ten Steps to a Cleaner Web Root http://www.securityfocus.com/infocus/1318
Request
GET /include/prototype-1.4.0/test/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 15:22:44 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1003
Connection: close
Content-Type: text/html

 99.  Possible sensitive directories

Severity Low
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/asp/
DetailsNo details are available.
TypeValidation
DescriptionA possible sensitive directory has been found. This check looks for known sensitive directories like: backup directories, database dumps, administration pages, temporary directories. Each of those directories may help an attacker to learn more about his target.
ImpactThis directory may expose sensitive information that may help an malicious user to prepare more advanced attacks.
RecommendationRestrict access to this directory or remove it from the website.
Reported by moduleDirectory checks
References
Security Focus : Ten Steps to a Cleaner Web Root http://www.securityfocus.com/infocus/1318
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/asp/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 15:17:51 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1500
Connection: close
Content-Type: text/html

 100.  Possible sensitive files

Severity Low
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/test.html
DetailsNo details are available.
TypeValidation
DescriptionA possible sensitive file has been found. This check looks for known sensitive files like: password files, configuration files, log files, include files, statistics data, database dumps. Each of those files may help an attacker to learn more about his target.
ImpactThis file may expose sensitive information that may help an malicious user to prepare more advanced attacks.
RecommendationRestrict access to this file or remove it from the website.
Reported by moduleDirectory checks
References
Security Focus : Ten Steps to a Cleaner Web Root http://www.securityfocus.com/infocus/1318
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/test.html HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 15:17:51 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;1354024-135b-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 4955
Connection: close
Content-Type: text/html

 101.  Possible sensitive directories

Severity Low
Affects /include/database/
DetailsNo details are available.
TypeValidation
DescriptionA possible sensitive directory has been found. This check looks for known sensitive directories like: backup directories, database dumps, administration pages, temporary directories. Each of those directories may help an attacker to learn more about his target.
ImpactThis directory may expose sensitive information that may help an malicious user to prepare more advanced attacks.
RecommendationRestrict access to this directory or remove it from the website.
Reported by moduleDirectory checks
References
Security Focus : Ten Steps to a Cleaner Web Root http://www.securityfocus.com/infocus/1318
Request
GET /include/database/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 15:13:16 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 755
Connection: close
Content-Type: text/html

 102.  Possible sensitive directories

Severity Low
Affects /include/install/
DetailsNo details are available.
TypeValidation
DescriptionA possible sensitive directory has been found. This check looks for known sensitive directories like: backup directories, database dumps, administration pages, temporary directories. Each of those directories may help an attacker to learn more about his target.
ImpactThis directory may expose sensitive information that may help an malicious user to prepare more advanced attacks.
RecommendationRestrict access to this directory or remove it from the website.
Reported by moduleDirectory checks
References
Security Focus : Ten Steps to a Cleaner Web Root http://www.securityfocus.com/infocus/1318
Request
GET /include/install/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 15:13:15 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 738
Connection: close
Content-Type: text/html

 103.  Possible sensitive directories

Severity Low
Affects /install/
DetailsNo details are available.
TypeValidation
DescriptionA possible sensitive directory has been found. This check looks for known sensitive directories like: backup directories, database dumps, administration pages, temporary directories. Each of those directories may help an attacker to learn more about his target.
ImpactThis directory may expose sensitive information that may help an malicious user to prepare more advanced attacks.
RecommendationRestrict access to this directory or remove it from the website.
Reported by moduleDirectory checks
References
Security Focus : Ten Steps to a Cleaner Web Root http://www.securityfocus.com/infocus/1318
Request
GET /install/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 15:13:06 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1487
Connection: close
Content-Type: text/html

 104.  Possible sensitive directories

Severity Low
Affects /data/
DetailsNo details are available.
TypeValidation
DescriptionA possible sensitive directory has been found. This check looks for known sensitive directories like: backup directories, database dumps, administration pages, temporary directories. Each of those directories may help an attacker to learn more about his target.
ImpactThis directory may expose sensitive information that may help an malicious user to prepare more advanced attacks.
RecommendationRestrict access to this directory or remove it from the website.
Reported by moduleDirectory checks
References
Security Focus : Ten Steps to a Cleaner Web Root http://www.securityfocus.com/infocus/1318
Request
GET /data/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 15:12:46 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 839
Connection: close
Content-Type: text/html

 105.  Possible sensitive directories

Severity Low
Affects /include/
DetailsNo details are available.
TypeValidation
DescriptionA possible sensitive directory has been found. This check looks for known sensitive directories like: backup directories, database dumps, administration pages, temporary directories. Each of those directories may help an attacker to learn more about his target.
ImpactThis directory may expose sensitive information that may help an malicious user to prepare more advanced attacks.
RecommendationRestrict access to this directory or remove it from the website.
Reported by moduleDirectory checks
References
Security Focus : Ten Steps to a Cleaner Web Root http://www.securityfocus.com/infocus/1318
Request
GET /include/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 15:12:46 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4285
Connection: close
Content-Type: text/html

 106.  Directory listing found

Severity Low
Affects /include
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:25 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4285
Connection: close
Content-Type: text/html

 107.  Directory listing found

Severity Low
Affects /include (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:47 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4285
Connection: close
Content-Type: text/html

 108.  Possible sensitive directories

Severity Low
Affects /database/
DetailsNo details are available.
TypeValidation
DescriptionA possible sensitive directory has been found. This check looks for known sensitive directories like: backup directories, database dumps, administration pages, temporary directories. Each of those directories may help an attacker to learn more about his target.
ImpactThis directory may expose sensitive information that may help an malicious user to prepare more advanced attacks.
RecommendationRestrict access to this directory or remove it from the website.
Reported by moduleDirectory checks
References
Security Focus : Ten Steps to a Cleaner Web Root http://www.securityfocus.com/infocus/1318
Request
GET /database/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Fri, 29 Sep 2006 15:13:07 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 616
Connection: close
Content-Type: text/html

 109.  Directory listing found

Severity Low
Affects /include/images (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/images/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/images/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:35 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2828
Connection: close
Content-Type: text/html

 110.  Directory listing found

Severity Low
Affects /include/js (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/js/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/js/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:57 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2872
Connection: close
Content-Type: text/html

 111.  Directory listing found

Severity Low
Affects /include/js (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/js/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/js/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:57 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2872
Connection: close
Content-Type: text/html

 112.  Directory listing found

Severity Low
Affects /include/js (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/js/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/js/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:57 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2872
Connection: close
Content-Type: text/html

 113.  Directory listing found

Severity Low
Affects /include/js (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/js/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/js/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2872
Connection: close
Content-Type: text/html

 114.  Directory listing found

Severity Low
Affects /include/js (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/js/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/js/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2872
Connection: close
Content-Type: text/html

 115.  Directory listing found

Severity Low
Affects /include/js (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/js/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/js/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2872
Connection: close
Content-Type: text/html

 116.  Directory listing found

Severity Low
Affects /include/js (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/js/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/js/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2872
Connection: close
Content-Type: text/html

 117.  Directory listing found

Severity Low
Affects /include/js
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/js/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:25 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2872
Connection: close
Content-Type: text/html

 118.  Directory listing found

Severity Low
Affects /include/images (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/images/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/images/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:47 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2828
Connection: close
Content-Type: text/html

 119.  Directory listing found

Severity Low
Affects /include/images (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/images/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/images/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:43 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2828
Connection: close
Content-Type: text/html

 120.  Directory listing found

Severity Low
Affects /include (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:47 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4285
Connection: close
Content-Type: text/html

 121.  Directory listing found

Severity Low
Affects /include/images (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/images/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/images/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:43 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2828
Connection: close
Content-Type: text/html

 122.  Directory listing found

Severity Low
Affects /include (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:36 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4285
Connection: close
Content-Type: text/html

 123.  Directory listing found

Severity Low
Affects /include/images (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/images/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/images/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:35 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2828
Connection: close
Content-Type: text/html

 124.  Directory listing found

Severity Low
Affects /include/images (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/images/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/images/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:35 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2828
Connection: close
Content-Type: text/html

 125.  Directory listing found

Severity Low
Affects /include/images (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/images/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/images/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:35 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2828
Connection: close
Content-Type: text/html

 126.  Directory listing found

Severity Low
Affects /include/images
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/images/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:25 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2828
Connection: close
Content-Type: text/html

 127.  Directory listing found

Severity Low
Affects /include (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:47 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4285
Connection: close
Content-Type: text/html

 128.  Broken links

Severity Low
Affects /modules/Emails/Emails.js
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Emails/Emails.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1/index.php
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:00:39 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 222
Connection: close
Content-Type: text/html; charset=iso-8859-1

 129.  Directory listing found

Severity Low
Affects /include (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:47 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4285
Connection: close
Content-Type: text/html

 130.  Directory listing found

Severity Low
Affects /include (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:36 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4285
Connection: close
Content-Type: text/html

 131.  Directory listing found

Severity Low
Affects /include (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:36 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4285
Connection: close
Content-Type: text/html

 132.  Directory listing found

Severity Low
Affects /include (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:36 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4285
Connection: close
Content-Type: text/html

 133.  Directory listing found

Severity Low
Affects /include/images (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/images/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/images/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:43 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2828
Connection: close
Content-Type: text/html

 134.  Directory listing found

Severity Low
Affects /include/js (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/js/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/js/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:57 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2872
Connection: close
Content-Type: text/html

 135.  Broken links

Severity Low
Affects /modules/Accounts/Accounts.js
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Accounts/Accounts.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1/index.php
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:00:39 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 226
Connection: close
Content-Type: text/html; charset=iso-8859-1

 136.  Broken links

Severity Low
Affects /modules/Users/{ORDER_BY}user_ip
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Users/{ORDER_BY}user_ip HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/modules/Users/ShowHistory.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:17 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 229
Connection: close
Content-Type: text/html; charset=iso-8859-1

 137.  Broken links

Severity Low
Affects /modules/Users/{ORDER_BY}login_time
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Users/{ORDER_BY}login_time HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/modules/Users/ShowHistory.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:17 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 232
Connection: close
Content-Type: text/html; charset=iso-8859-1

 138.  Broken links

Severity Low
Affects /modules/Users/{ORDER_BY}logout_time
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Users/{ORDER_BY}logout_time HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/modules/Users/ShowHistory.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:17 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 233
Connection: close
Content-Type: text/html; charset=iso-8859-1

 139.  Broken links

Severity Low
Affects /modules/uploads/index.php
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/uploads/index.php?module=uploads&amp;action=add2db&amp;return_module= HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/modules/uploads/upload.php
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:17 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 223
Connection: close
Content-Type: text/html; charset=iso-8859-1

 140.  Broken links

Severity Low
Affects /modules/uploads/themes/style.css
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/uploads/themes/style.css HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/modules/uploads/upload.php
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:17 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 230
Connection: close
Content-Type: text/html; charset=iso-8859-1

 141.  Broken links

Severity Low
Affects /modules/uploads/index.php (GET module=uploads&action=add2db&return_module=; POST MAX_FILE_SIZE=1000000&return_module=&return_action=&return_id=&filename=&txtDescription=&save=%26nbsp%3BAttach%26nbsp%3B&cancel=Cancel)
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
POST /modules/uploads/index.php?module=uploads&amp;action=add2db&amp;return_module= HTTP/1.0
Accept: */*
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Content-Length: 134
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/modules/uploads/upload.php
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:17 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 223
Connection: close
Content-Type: text/html; charset=iso-8859-1

 142.  File inputs accepted

Severity Low
Affects /include/fckeditor/editor/dialog/fck_flash.html
DetailsNo details are available.
TypeInformational
DescriptionBy this form input is possible to upload a file to the server.
ImpactUser may upload malicious files to server.
RecommendationCheck if the script inputs are properly validated.
Reported by moduleCrawler
References
Request
GET /include/fckeditor/editor/dialog/fck_flash.html HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:20 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;1354034-14c0-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 5312
Connection: close
Content-Type: text/html

 143.  File inputs accepted

Severity Low
Affects /include/fckeditor/editor/dialog/fck_image.html
DetailsNo details are available.
TypeInformational
DescriptionBy this form input is possible to upload a file to the server.
ImpactUser may upload malicious files to server.
RecommendationCheck if the script inputs are properly validated.
Reported by moduleCrawler
References
Request
GET /include/fckeditor/editor/dialog/fck_image.html HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:20 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;1354048-2380-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 9088
Connection: close
Content-Type: text/html

 144.  File inputs accepted

Severity Low
Affects /include/fckeditor/editor/dialog/fck_link.html
DetailsNo details are available.
TypeInformational
DescriptionBy this form input is possible to upload a file to the server.
ImpactUser may upload malicious files to server.
RecommendationCheck if the script inputs are properly validated.
Reported by moduleCrawler
References
Request
GET /include/fckeditor/editor/dialog/fck_link.html HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:20 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;1354057-305e-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 12382
Connection: close
Content-Type: text/html

 145.  Broken links

Severity Low
Affects /modules/Users/index.php (GET module=Users&action=ListView&query=true&last_name=I)
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Users/index.php?module=Users&amp;action=ListView&amp;query=true&amp;last_name=I HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/modules/Users/SearchForm.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:17 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 221
Connection: close
Content-Type: text/html; charset=iso-8859-1

 146.  Broken links

Severity Low
Affects /include/fckeditor/editor/dialog/fck_flash/fck_flash_preview.html
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /include/fckeditor/editor/dialog/fck_flash/fck_flash_preview.html HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/fck_flash.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:32 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 262
Connection: close
Content-Type: text/html; charset=iso-8859-1

 147.  Broken links

Severity Low
Affects /modules/Users/index.php (GET module=Users&action=ListView&query=true&last_name=H)
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Users/index.php?module=Users&amp;action=ListView&amp;query=true&amp;last_name=H HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/modules/Users/SearchForm.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:17 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 221
Connection: close
Content-Type: text/html; charset=iso-8859-1

 148.  File inputs accepted

Severity Low
Affects /include/fckeditor/editor/dialog/fck_flash.html
DetailsNo details are available.
TypeInformational
DescriptionBy this form input is possible to upload a file to the server.
ImpactUser may upload malicious files to server.
RecommendationCheck if the script inputs are properly validated.
Reported by moduleCrawler
References
Request
GET /include/fckeditor/editor/dialog/fck_flash.html HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:20 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;1354034-14c0-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 5312
Connection: close
Content-Type: text/html

 149.  Directory listing found

Severity Low
Affects /include/scriptaculous (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/scriptaculous/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/scriptaculous/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:57 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1593
Connection: close
Content-Type: text/html

 150.  File inputs accepted

Severity Low
Affects /include/fckeditor/editor/dialog/fck_image.html
DetailsNo details are available.
TypeInformational
DescriptionBy this form input is possible to upload a file to the server.
ImpactUser may upload malicious files to server.
RecommendationCheck if the script inputs are properly validated.
Reported by moduleCrawler
References
Request
GET /include/fckeditor/editor/dialog/fck_image.html HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:20 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;1354048-2380-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 9088
Connection: close
Content-Type: text/html

 151.  File inputs accepted

Severity Low
Affects /include/fckeditor/editor/dialog/fck_link.html
DetailsNo details are available.
TypeInformational
DescriptionBy this form input is possible to upload a file to the server.
ImpactUser may upload malicious files to server.
RecommendationCheck if the script inputs are properly validated.
Reported by moduleCrawler
References
Request
GET /include/fckeditor/editor/dialog/fck_link.html HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:20 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;1354057-305e-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 12382
Connection: close
Content-Type: text/html

 152.  Broken links

Severity Low
Affects /include/fckeditor/editor/dialog/common/common/fcknumericfield.htc
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /include/fckeditor/editor/dialog/common/common/fcknumericfield.htc HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/common/fck_dialog_common.css
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:39 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 263
Connection: close
Content-Type: text/html; charset=iso-8859-1

 153.  File inputs accepted

Severity Low
Affects /include/fckeditor/editor/filemanager/browser/default/frmupload.html
DetailsNo details are available.
TypeInformational
DescriptionBy this form input is possible to upload a file to the server.
ImpactUser may upload malicious files to server.
RecommendationCheck if the script inputs are properly validated.
Reported by moduleCrawler
References
Request
GET /include/fckeditor/editor/filemanager/browser/default/frmupload.html HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/filemanager/browser/default/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:41 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;115805f-d20-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 3360
Connection: close
Content-Type: text/html

 154.  File inputs accepted

Severity Low
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/test.html
DetailsNo details are available.
TypeInformational
DescriptionBy this form input is possible to upload a file to the server.
ImpactUser may upload malicious files to server.
RecommendationCheck if the script inputs are properly validated.
Reported by moduleCrawler
References
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/test.html HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/filemanager/browser/default/connectors/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:46 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;1354024-135b-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 4955
Connection: close
Content-Type: text/html

 155.  File inputs accepted

Severity Low
Affects /include/fckeditor/editor/filemanager/browser/default/frmupload.html
DetailsNo details are available.
TypeInformational
DescriptionBy this form input is possible to upload a file to the server.
ImpactUser may upload malicious files to server.
RecommendationCheck if the script inputs are properly validated.
Reported by moduleCrawler
References
Request
GET /include/fckeditor/editor/filemanager/browser/default/frmupload.html HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/filemanager/browser/default/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:41 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;115805f-d20-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 3360
Connection: close
Content-Type: text/html

 156.  File inputs accepted

Severity Low
Affects /include/fckeditor/editor/filemanager/browser/default/connectors/test.html
DetailsNo details are available.
TypeInformational
DescriptionBy this form input is possible to upload a file to the server.
ImpactUser may upload malicious files to server.
RecommendationCheck if the script inputs are properly validated.
Reported by moduleCrawler
References
Request
GET /include/fckeditor/editor/filemanager/browser/default/connectors/test.html HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/filemanager/browser/default/connectors/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:46 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Last-Modified: Fri, 15 Sep 2006 21:38:30 GMT
ETag: &quot;1354024-135b-d8618180&quot;
Accept-Ranges: bytes
Content-Length: 4955
Connection: close
Content-Type: text/html

 157.  TRACE Method Enabled

Severity Low
Affects Web Server
DetailsNo details are available.
TypeValidation
DescriptionHTTP TRACE method is enabled on this web server. In the presence of other cross-domain vulnerabilities in web browsers, sensitive header information could be read from any domains that support the HTTP TRACE method.
ImpactAttackers may abuse HTTP TRACE functionality to gain access to information in HTTP headers such as cookies and authentication data.
RecommendationDisable TRACE Method on the web server.
Reported by moduleCGI Tester
References
W3C - RFC 2616http://www.w3.org/Protocols/rfc2616/rfc2616-sec9.html
US-CERT VU#867593http://www.kb.cert.org/vuls/id/867593
IIS 6 WWW Service Registry Entrieshttp://www.microsoft.com/resources/documentation/iis/6/all/proddocs/en-us/ref_reg_wwwservice.mspx
Cross-site tracing (XST)http://www.cgisecurity.com/lib/WH-WhitePaper_XST_ebook.pdf
Request
TRACE /TRACE_test HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:03:04 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Connection: close
Content-Type: message/http

 158.  Broken links

Severity Low
Affects /include/fckeditor/editor/dialog/fck_flash/fck_flash.js
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /include/fckeditor/editor/dialog/fck_flash/fck_flash.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/fck_flash.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:32 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 252
Connection: close
Content-Type: text/html; charset=iso-8859-1

 159.  Broken links

Severity Low
Affects /themes/alphagrey/include/style.css
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /themes/alphagrey/include/style.css HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/themes/alphagrey/loginheader.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:09 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 232
Connection: close
Content-Type: text/html; charset=iso-8859-1

 160.  Broken links

Severity Low
Affects /modules/Potentials/Potentials.js
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Potentials/Potentials.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1/index.php
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:00:39 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 230
Connection: close
Content-Type: text/html; charset=iso-8859-1

 161.  Broken links

Severity Low
Affects /modules/Contacts/Contacts.js
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Contacts/Contacts.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1/index.php
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:00:39 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 226
Connection: close
Content-Type: text/html; charset=iso-8859-1

 162.  Broken links

Severity Low
Affects /modules/Notes/Notes.js
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Notes/Notes.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1/index.php
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:00:39 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 220
Connection: close
Content-Type: text/html; charset=iso-8859-1

 163.  Broken links

Severity Low
Affects /modules/Calendar/Calendar.js
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Calendar/Calendar.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1/index.php
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:00:39 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 226
Connection: close
Content-Type: text/html; charset=iso-8859-1

 164.  Broken links

Severity Low
Affects /modules/Products/Products.js
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Products/Products.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1/index.php
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:00:39 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 226
Connection: close
Content-Type: text/html; charset=iso-8859-1

 165.  Broken links

Severity Low
Affects /modules/Vendors/Vendors.js
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Vendors/Vendors.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1/index.php
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:00:39 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 224
Connection: close
Content-Type: text/html; charset=iso-8859-1

 166.  Broken links

Severity Low
Affects /modules/PriceBooks/PriceBooks.js
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/PriceBooks/PriceBooks.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1/index.php
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:00:39 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 230
Connection: close
Content-Type: text/html; charset=iso-8859-1

 167.  Broken links

Severity Low
Affects /modules/Quotes/Quotes.js
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Quotes/Quotes.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1/index.php
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:00:39 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 222
Connection: close
Content-Type: text/html; charset=iso-8859-1

 168.  Broken links

Severity Low
Affects /modules/Campaigns/Campaigns.js
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Campaigns/Campaigns.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1/index.php
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:00:39 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 228
Connection: close
Content-Type: text/html; charset=iso-8859-1

 169.  Broken links

Severity Low
Affects /modules/Leads/Leads.js
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Leads/Leads.js HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1/index.php
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:00:39 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 220
Connection: close
Content-Type: text/html; charset=iso-8859-1

 170.  Broken links

Severity Low
Affects /modules/Users/{ORDER_BY}user_name
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Users/{ORDER_BY}user_name HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/modules/Users/ShowHistory.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:17 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 231
Connection: close
Content-Type: text/html; charset=iso-8859-1

 171.  File inputs accepted

Severity Low
Affects /modules/uploads/index.php
DetailsNo details are available.
TypeInformational
DescriptionBy this form input is possible to upload a file to the server.
ImpactUser may upload malicious files to server.
RecommendationCheck if the script inputs are properly validated.
Reported by moduleCrawler
References
Request
Response

 172.  Broken links

Severity Low
Affects /style.css
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /style.css HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1/index.php
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:00:25 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 207
Connection: close
Content-Type: text/html; charset=iso-8859-1

 173.  Broken links

Severity Low
Affects /themes/woodspice/include/style.css
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /themes/woodspice/include/style.css HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/themes/woodspice/loginheader.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:09 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 232
Connection: close
Content-Type: text/html; charset=iso-8859-1

 174.  Broken links

Severity Low
Affects /modules/Users/index.php
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Users/index.php HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/modules/Users/SearchForm.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:16 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 221
Connection: close
Content-Type: text/html; charset=iso-8859-1

 175.  Broken links

Severity Low
Affects /modules/Users/index.php (GET module=Users&action=ListView&advanced=true)
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Users/index.php?module=Users&amp;action=ListView&amp;advanced=true HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/modules/Users/SearchForm.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:16 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 221
Connection: close
Content-Type: text/html; charset=iso-8859-1

 176.  Broken links

Severity Low
Affects /modules/Users/index.php (GET module=Users&action=ListView&query=true&last_name=B)
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Users/index.php?module=Users&amp;action=ListView&amp;query=true&amp;last_name=B HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/modules/Users/SearchForm.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:16 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 221
Connection: close
Content-Type: text/html; charset=iso-8859-1

 177.  Broken links

Severity Low
Affects /modules/Users/index.php (GET module=Users&action=ListView&query=true&last_name=A)
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Users/index.php?module=Users&amp;action=ListView&amp;query=true&amp;last_name=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/modules/Users/SearchForm.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:16 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 221
Connection: close
Content-Type: text/html; charset=iso-8859-1

 178.  Broken links

Severity Low
Affects /modules/Users/index.php (GET module=Users&action=ListView&query=true&last_name=C)
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Users/index.php?module=Users&amp;action=ListView&amp;query=true&amp;last_name=C HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/modules/Users/SearchForm.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:17 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 221
Connection: close
Content-Type: text/html; charset=iso-8859-1

 179.  Broken links

Severity Low
Affects /modules/Users/index.php (GET module=Users&action=ListView&query=true&last_name=D)
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Users/index.php?module=Users&amp;action=ListView&amp;query=true&amp;last_name=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/modules/Users/SearchForm.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:17 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 221
Connection: close
Content-Type: text/html; charset=iso-8859-1

 180.  Broken links

Severity Low
Affects /modules/Users/index.php (GET module=Users&action=ListView&query=true&last_name=E)
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Users/index.php?module=Users&amp;action=ListView&amp;query=true&amp;last_name=E HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/modules/Users/SearchForm.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:17 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 221
Connection: close
Content-Type: text/html; charset=iso-8859-1

 181.  Broken links

Severity Low
Affects /modules/Users/index.php (GET module=Users&action=ListView&query=true&last_name=F)
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Users/index.php?module=Users&amp;action=ListView&amp;query=true&amp;last_name=F HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/modules/Users/SearchForm.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:17 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 221
Connection: close
Content-Type: text/html; charset=iso-8859-1

 182.  Broken links

Severity Low
Affects /modules/Users/index.php (GET module=Users&action=ListView&query=true&last_name=G)
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /modules/Users/index.php?module=Users&amp;action=ListView&amp;query=true&amp;last_name=G HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/modules/Users/SearchForm.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:01:17 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 221
Connection: close
Content-Type: text/html; charset=iso-8859-1

 183.  Broken links

Severity Low
Affects /themes/bluelagoon/include/style.css
DetailsNo details are available.
TypeInformational
DescriptionThis page was found as link but is inaccessible.
ImpactProblems navigating the site.
RecommendationRemove the links to this file or make this available.
Reported by moduleCrawler
References
Request
GET /themes/bluelagoon/include/style.css HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/themes/bluelagoon/loginheader.html
Response
HTTP/1.1 404 Not Found
Date: Thu, 28 Sep 2006 20:00:55 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 233
Connection: close
Content-Type: text/html; charset=iso-8859-1

 184.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/internals (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/internals/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/internals/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:30 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 6015
Connection: close
Content-Type: text/html

 185.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/globals (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/globals/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/globals/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:30 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 830
Connection: close
Content-Type: text/html

 186.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/globals (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/globals/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/globals/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:30 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 830
Connection: close
Content-Type: text/html

 187.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/globals (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/globals/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/globals/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 830
Connection: close
Content-Type: text/html

 188.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/globals (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/globals/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/globals/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 830
Connection: close
Content-Type: text/html

 189.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/globals (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/globals/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/globals/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 830
Connection: close
Content-Type: text/html

 190.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/globals (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/globals/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/globals/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 830
Connection: close
Content-Type: text/html

 191.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/internals
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/internals/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:18 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 6015
Connection: close
Content-Type: text/html

 192.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/internals (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/internals/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/internals/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:30 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 6015
Connection: close
Content-Type: text/html

 193.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/css (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/css/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/css/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:19 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1050
Connection: close
Content-Type: text/html

 194.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/internals (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/internals/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/internals/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:30 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 6015
Connection: close
Content-Type: text/html

 195.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/globals
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/globals/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:18 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 830
Connection: close
Content-Type: text/html

 196.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/internals (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/internals/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/internals/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 6015
Connection: close
Content-Type: text/html

 197.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/internals (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/internals/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/internals/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 6015
Connection: close
Content-Type: text/html

 198.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/internals (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/internals/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/internals/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 6015
Connection: close
Content-Type: text/html

 199.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/internals (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/internals/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/internals/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 6015
Connection: close
Content-Type: text/html

 200.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/css
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/css/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:04 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1050
Connection: close
Content-Type: text/html

 201.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/css (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/css/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/css/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:19 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1050
Connection: close
Content-Type: text/html

 202.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/css (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/css/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/css/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:19 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1050
Connection: close
Content-Type: text/html

 203.  Directory listing found

Severity Low
Affects /include/scriptaculous (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/scriptaculous/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/scriptaculous/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:42 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1593
Connection: close
Content-Type: text/html

 204.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/internals (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/internals/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/internals/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:30 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 6015
Connection: close
Content-Type: text/html

 205.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/commandclasses
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/commandclasses/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:18 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1778
Connection: close
Content-Type: text/html

 206.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:30 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1028
Connection: close
Content-Type: text/html

 207.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/classes
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/classes/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:18 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 3783
Connection: close
Content-Type: text/html

 208.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/classes (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/classes/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/classes/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:29 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 3783
Connection: close
Content-Type: text/html

 209.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/classes (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/classes/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/classes/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:29 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 3783
Connection: close
Content-Type: text/html

 210.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/classes (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/classes/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/classes/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:29 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 3783
Connection: close
Content-Type: text/html

 211.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/classes (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/classes/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/classes/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:29 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 3783
Connection: close
Content-Type: text/html

 212.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/classes (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/classes/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/classes/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:37 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 3783
Connection: close
Content-Type: text/html

 213.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/classes (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/classes/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/classes/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:37 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 3783
Connection: close
Content-Type: text/html

 214.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/globals (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/globals/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/globals/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:30 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 830
Connection: close
Content-Type: text/html

 215.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/classes (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/classes/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/classes/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 3783
Connection: close
Content-Type: text/html

 216.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/globals (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/globals/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/globals/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:30 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 830
Connection: close
Content-Type: text/html

 217.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/commandclasses (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/commandclasses/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/commandclasses/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:30 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1778
Connection: close
Content-Type: text/html

 218.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/commandclasses (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/commandclasses/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/commandclasses/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:30 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1778
Connection: close
Content-Type: text/html

 219.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/commandclasses (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/commandclasses/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/commandclasses/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:30 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1778
Connection: close
Content-Type: text/html

 220.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/commandclasses (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/commandclasses/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/commandclasses/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:30 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1778
Connection: close
Content-Type: text/html

 221.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/commandclasses (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/commandclasses/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/commandclasses/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1778
Connection: close
Content-Type: text/html

 222.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/commandclasses (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/commandclasses/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/commandclasses/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1778
Connection: close
Content-Type: text/html

 223.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/commandclasses (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/commandclasses/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/commandclasses/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1778
Connection: close
Content-Type: text/html

 224.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/commandclasses (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/commandclasses/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/commandclasses/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1778
Connection: close
Content-Type: text/html

 225.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/css (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/css/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/css/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:31 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1050
Connection: close
Content-Type: text/html

 226.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source/classes (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/classes/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/classes/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 3783
Connection: close
Content-Type: text/html

 227.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/common/images (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/common/images/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/common/images/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 951
Connection: close
Content-Type: text/html

 228.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/common (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/common/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/common/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:31 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1197
Connection: close
Content-Type: text/html

 229.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/common (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/common/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/common/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:31 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1197
Connection: close
Content-Type: text/html

 230.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/common (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/common/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/common/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:32 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1197
Connection: close
Content-Type: text/html

 231.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/common (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/common/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/common/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:32 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1197
Connection: close
Content-Type: text/html

 232.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/common (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/common/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/common/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1197
Connection: close
Content-Type: text/html

 233.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/common (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/common/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/common/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1197
Connection: close
Content-Type: text/html

 234.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/common (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/common/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/common/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1197
Connection: close
Content-Type: text/html

 235.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/common (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/common/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/common/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1197
Connection: close
Content-Type: text/html

 236.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/css (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/css/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/css/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:19 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1050
Connection: close
Content-Type: text/html

 237.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/common/images (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/common/images/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/common/images/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 951
Connection: close
Content-Type: text/html

 238.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:31 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4787
Connection: close
Content-Type: text/html

 239.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/common/images (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/common/images/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/common/images/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 951
Connection: close
Content-Type: text/html

 240.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/common/images (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/common/images/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/common/images/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 951
Connection: close
Content-Type: text/html

 241.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/common/images (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/common/images/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/common/images/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:46 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 951
Connection: close
Content-Type: text/html

 242.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/common/images (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/common/images/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/common/images/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:46 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 951
Connection: close
Content-Type: text/html

 243.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/common/images (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/common/images/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/common/images/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:46 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 951
Connection: close
Content-Type: text/html

 244.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/common/images (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/common/images/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/common/images/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:46 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 951
Connection: close
Content-Type: text/html

 245.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/fck_about
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/fck_about/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:20 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 945
Connection: close
Content-Type: text/html

 246.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/fck_about (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/fck_about/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/fck_about/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:32 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 945
Connection: close
Content-Type: text/html

 247.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/common/images
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/common/images/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/common/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:32 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 951
Connection: close
Content-Type: text/html

 248.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/css/behaviors (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/css/behaviors/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/css/behaviors/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1434
Connection: close
Content-Type: text/html

 249.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/css (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/css/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/css/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:31 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1050
Connection: close
Content-Type: text/html

 250.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/css (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/css/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/css/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:31 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1050
Connection: close
Content-Type: text/html

 251.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/css (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/css/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/css/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:31 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1050
Connection: close
Content-Type: text/html

 252.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/css/behaviors
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/css/behaviors/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/css/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:19 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1434
Connection: close
Content-Type: text/html

 253.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/css/behaviors (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/css/behaviors/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/css/behaviors/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:31 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1434
Connection: close
Content-Type: text/html

 254.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/css/behaviors (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/css/behaviors/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/css/behaviors/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:31 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1434
Connection: close
Content-Type: text/html

 255.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/css/behaviors (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/css/behaviors/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/css/behaviors/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:31 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1434
Connection: close
Content-Type: text/html

 256.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/css/behaviors (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/css/behaviors/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/css/behaviors/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:31 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1434
Connection: close
Content-Type: text/html

 257.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog/common
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/common/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:20 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1197
Connection: close
Content-Type: text/html

 258.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/css/behaviors (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/css/behaviors/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/css/behaviors/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1434
Connection: close
Content-Type: text/html

 259.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:31 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4787
Connection: close
Content-Type: text/html

 260.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/css/behaviors (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/css/behaviors/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/css/behaviors/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1434
Connection: close
Content-Type: text/html

 261.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:04 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4787
Connection: close
Content-Type: text/html

 262.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:19 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4787
Connection: close
Content-Type: text/html

 263.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:19 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4787
Connection: close
Content-Type: text/html

 264.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:19 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4787
Connection: close
Content-Type: text/html

 265.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:19 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4787
Connection: close
Content-Type: text/html

 266.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:31 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4787
Connection: close
Content-Type: text/html

 267.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/dialog (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/dialog/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/dialog/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:31 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 4787
Connection: close
Content-Type: text/html

 268.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:29 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1028
Connection: close
Content-Type: text/html

 269.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/css/behaviors (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/css/behaviors/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/css/behaviors/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:38 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1434
Connection: close
Content-Type: text/html

 270.  Directory listing found

Severity Low
Affects /include/ListView (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/ListView/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/ListView/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:03 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 757
Connection: close
Content-Type: text/html

 271.  Directory listing found

Severity Low
Affects /include/Ajax (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/Ajax/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/Ajax/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:02 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 744
Connection: close
Content-Type: text/html

 272.  Directory listing found

Severity Low
Affects /include/Ajax (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/Ajax/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/Ajax/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:02 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 744
Connection: close
Content-Type: text/html

 273.  Directory listing found

Severity Low
Affects /include/Ajax (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/Ajax/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/Ajax/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:02 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 744
Connection: close
Content-Type: text/html

 274.  Directory listing found

Severity Low
Affects /include/ListView
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/ListView/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:37 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 757
Connection: close
Content-Type: text/html

 275.  Directory listing found

Severity Low
Affects /include/ListView (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/ListView/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/ListView/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:48 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 757
Connection: close
Content-Type: text/html

 276.  Directory listing found

Severity Low
Affects /include/ListView (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/ListView/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/ListView/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:49 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 757
Connection: close
Content-Type: text/html

 277.  Directory listing found

Severity Low
Affects /include/ListView (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/ListView/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/ListView/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:49 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 757
Connection: close
Content-Type: text/html

 278.  Directory listing found

Severity Low
Affects /include/ListView (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/ListView/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/ListView/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:49 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 757
Connection: close
Content-Type: text/html

 279.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:29 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1028
Connection: close
Content-Type: text/html

 280.  Directory listing found

Severity Low
Affects /include/ListView (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/ListView/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/ListView/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:03 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 757
Connection: close
Content-Type: text/html

 281.  Directory listing found

Severity Low
Affects /include/Ajax (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/Ajax/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/Ajax/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:48 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 744
Connection: close
Content-Type: text/html

 282.  Directory listing found

Severity Low
Affects /include/ListView (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/ListView/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/ListView/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:03 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 757
Connection: close
Content-Type: text/html

 283.  Directory listing found

Severity Low
Affects /include/clock
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/clock/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:37 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 621
Connection: close
Content-Type: text/html

 284.  Directory listing found

Severity Low
Affects /include/clock (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/clock/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/clock/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:51 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 621
Connection: close
Content-Type: text/html

 285.  Directory listing found

Severity Low
Affects /include/clock (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/clock/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/clock/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:51 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 621
Connection: close
Content-Type: text/html

 286.  Directory listing found

Severity Low
Affects /include/clock (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/clock/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/clock/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:51 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 621
Connection: close
Content-Type: text/html

 287.  Directory listing found

Severity Low
Affects /include/clock (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/clock/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/clock/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:51 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 621
Connection: close
Content-Type: text/html

 288.  Directory listing found

Severity Low
Affects /include/clock (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/clock/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/clock/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:06 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 621
Connection: close
Content-Type: text/html

 289.  Directory listing found

Severity Low
Affects /include/clock (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/clock/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/clock/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:06 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 621
Connection: close
Content-Type: text/html

 290.  Directory listing found

Severity Low
Affects /include/ListView (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/ListView/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/ListView/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:02 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 757
Connection: close
Content-Type: text/html

 291.  Directory listing found

Severity Low
Affects /include/calculator (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/calculator/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/calculator/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:42 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 745
Connection: close
Content-Type: text/html

 292.  Directory listing found

Severity Low
Affects /include/scriptaculous (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/scriptaculous/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/scriptaculous/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:42 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1593
Connection: close
Content-Type: text/html

 293.  Directory listing found

Severity Low
Affects /include/scriptaculous (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/scriptaculous/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/scriptaculous/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:42 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1593
Connection: close
Content-Type: text/html

 294.  Directory listing found

Severity Low
Affects /include/scriptaculous (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/scriptaculous/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/scriptaculous/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:42 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1593
Connection: close
Content-Type: text/html

 295.  User credentials are sent in clear text

Severity Low
Affects /
DetailsNo details are available.
TypeInformational
DescriptionIt seemes that user credentials are sent to /index.php in clear text.
ImpactA third party may be able to read the user credentials by intercepting an unencrypted HTTP connection.
RecommendationBecause user credentials usually are considered sensitive information, it is recommended to be sent to the server over an encrypted connection.
Reported by moduleCrawler
References
Request
GET / HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:21 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
X-Powered-By: PHP/4.3.10-16
Set-Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176; path=/
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Content-Length: 7402
Connection: close
Content-Type: text/html; charset=ISO-8859-1

 296.  Directory listing found

Severity Low
Affects /include/scriptaculous (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/scriptaculous/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/scriptaculous/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:57 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1593
Connection: close
Content-Type: text/html

 297.  Directory listing found

Severity Low
Affects /include/scriptaculous (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/scriptaculous/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/scriptaculous/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:57 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1593
Connection: close
Content-Type: text/html

 298.  Directory listing found

Severity Low
Affects /include/scriptaculous (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/scriptaculous/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/scriptaculous/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:57 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1593
Connection: close
Content-Type: text/html

 299.  Directory listing found

Severity Low
Affects /include/calculator
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/calculator/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:35 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 745
Connection: close
Content-Type: text/html

 300.  Directory listing found

Severity Low
Affects /include/Ajax (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/Ajax/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/Ajax/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:01 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 744
Connection: close
Content-Type: text/html

 301.  Directory listing found

Severity Low
Affects /include/calculator (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/calculator/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/calculator/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:42 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 745
Connection: close
Content-Type: text/html

 302.  Directory listing found

Severity Low
Affects /include/Ajax (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/Ajax/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/Ajax/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:48 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 744
Connection: close
Content-Type: text/html

 303.  Directory listing found

Severity Low
Affects /include/calculator (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/calculator/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/calculator/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:43 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 745
Connection: close
Content-Type: text/html

 304.  Directory listing found

Severity Low
Affects /include/calculator (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/calculator/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/calculator/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:57 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 745
Connection: close
Content-Type: text/html

 305.  Directory listing found

Severity Low
Affects /include/calculator (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/calculator/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/calculator/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:57 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 745
Connection: close
Content-Type: text/html

 306.  Directory listing found

Severity Low
Affects /include/calculator (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/calculator/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/calculator/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:57 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 745
Connection: close
Content-Type: text/html

 307.  Directory listing found

Severity Low
Affects /include/calculator (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/calculator/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/calculator/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:57 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 745
Connection: close
Content-Type: text/html

 308.  Directory listing found

Severity Low
Affects /include/Ajax
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/Ajax/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:36 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 744
Connection: close
Content-Type: text/html

 309.  Directory listing found

Severity Low
Affects /include/Ajax (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/Ajax/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/Ajax/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:47 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 744
Connection: close
Content-Type: text/html

 310.  Directory listing found

Severity Low
Affects /include/Ajax (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/Ajax/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/Ajax/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:48 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 744
Connection: close
Content-Type: text/html

 311.  Directory listing found

Severity Low
Affects /include/database
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/database/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:37 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 755
Connection: close
Content-Type: text/html

 312.  Directory listing found

Severity Low
Affects /include/calculator (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/calculator/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/calculator/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:42 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 745
Connection: close
Content-Type: text/html

 313.  Directory listing found

Severity Low
Affects /include/fckeditor/editor (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:18 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2405
Connection: close
Content-Type: text/html

 314.  Directory listing found

Severity Low
Affects /include/clock (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/clock/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/clock/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:06 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 621
Connection: close
Content-Type: text/html

 315.  Directory listing found

Severity Low
Affects /include/fckeditor (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:03 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1348
Connection: close
Content-Type: text/html

 316.  Directory listing found

Severity Low
Affects /include/fckeditor (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:03 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1348
Connection: close
Content-Type: text/html

 317.  Directory listing found

Severity Low
Affects /include/fckeditor (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:04 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1348
Connection: close
Content-Type: text/html

 318.  Directory listing found

Severity Low
Affects /include/fckeditor (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:04 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1348
Connection: close
Content-Type: text/html

 319.  Directory listing found

Severity Low
Affects /include/fckeditor/editor
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:50 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2405
Connection: close
Content-Type: text/html

 320.  Directory listing found

Severity Low
Affects /include/fckeditor/editor (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:04 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2405
Connection: close
Content-Type: text/html

 321.  Directory listing found

Severity Low
Affects /include/fckeditor/editor (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:04 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2405
Connection: close
Content-Type: text/html

 322.  Directory listing found

Severity Low
Affects /include/fckeditor (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:50 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1348
Connection: close
Content-Type: text/html

 323.  Directory listing found

Severity Low
Affects /include/fckeditor/editor (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:04 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2405
Connection: close
Content-Type: text/html

 324.  Directory listing found

Severity Low
Affects /include/fckeditor (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:50 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1348
Connection: close
Content-Type: text/html

 325.  Directory listing found

Severity Low
Affects /include/fckeditor/editor (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:18 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2405
Connection: close
Content-Type: text/html

 326.  Directory listing found

Severity Low
Affects /include/fckeditor/editor (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:18 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2405
Connection: close
Content-Type: text/html

 327.  Directory listing found

Severity Low
Affects /include/fckeditor/editor (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:18 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2405
Connection: close
Content-Type: text/html

 328.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:04 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1028
Connection: close
Content-Type: text/html

 329.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:18 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1028
Connection: close
Content-Type: text/html

 330.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:18 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1028
Connection: close
Content-Type: text/html

 331.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:18 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1028
Connection: close
Content-Type: text/html

 332.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:18 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1028
Connection: close
Content-Type: text/html

 333.  Directory listing found

Severity Low
Affects /include/scriptaculous
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/scriptaculous/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:35 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1593
Connection: close
Content-Type: text/html

 334.  Directory listing found

Severity Low
Affects /include/fckeditor/editor (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:04 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 2405
Connection: close
Content-Type: text/html

 335.  Directory listing found

Severity Low
Affects /include/db_backup (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/db_backup/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/db_backup/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:50 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 745
Connection: close
Content-Type: text/html

 336.  Directory listing found

Severity Low
Affects /include/fckeditor/editor/_source (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/editor/_source/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/editor/_source/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:29 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1028
Connection: close
Content-Type: text/html

 337.  Directory listing found

Severity Low
Affects /include/database (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/database/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/database/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:49 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 755
Connection: close
Content-Type: text/html

 338.  Directory listing found

Severity Low
Affects /include/database (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/database/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/database/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:49 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 755
Connection: close
Content-Type: text/html

 339.  Directory listing found

Severity Low
Affects /include/database (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/database/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/database/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:49 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 755
Connection: close
Content-Type: text/html

 340.  Directory listing found

Severity Low
Affects /include/database (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/database/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/database/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:49 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 755
Connection: close
Content-Type: text/html

 341.  Directory listing found

Severity Low
Affects /include/database (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/database/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/database/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:03 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 755
Connection: close
Content-Type: text/html

 342.  Directory listing found

Severity Low
Affects /include/database (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/database/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/database/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:03 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 755
Connection: close
Content-Type: text/html

 343.  Directory listing found

Severity Low
Affects /include/database (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/database/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/database/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:03 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 755
Connection: close
Content-Type: text/html

 344.  Directory listing found

Severity Low
Affects /include/fckeditor (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:50 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1348
Connection: close
Content-Type: text/html

 345.  Directory listing found

Severity Low
Affects /include/db_backup
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/db_backup/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:37 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 745
Connection: close
Content-Type: text/html

 346.  Directory listing found

Severity Low
Affects /include/clock (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/clock/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/clock/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:06 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 621
Connection: close
Content-Type: text/html

 347.  Directory listing found

Severity Low
Affects /include/db_backup (GET C=M;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/db_backup/?C=M;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/db_backup/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:50 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 745
Connection: close
Content-Type: text/html

 348.  Directory listing found

Severity Low
Affects /include/db_backup (GET C=S;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/db_backup/?C=S;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/db_backup/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:50 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 745
Connection: close
Content-Type: text/html

 349.  Directory listing found

Severity Low
Affects /include/db_backup (GET C=D;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/db_backup/?C=D;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/db_backup/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:50 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 745
Connection: close
Content-Type: text/html

 350.  Directory listing found

Severity Low
Affects /include/db_backup (GET C=N;O=A)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/db_backup/?C=N;O=A HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/db_backup/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:03 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 745
Connection: close
Content-Type: text/html

 351.  Directory listing found

Severity Low
Affects /include/db_backup (GET C=M;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/db_backup/?C=M;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/db_backup/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:03 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 745
Connection: close
Content-Type: text/html

 352.  Directory listing found

Severity Low
Affects /include/db_backup (GET C=D;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/db_backup/?C=D;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/db_backup/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:03 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 745
Connection: close
Content-Type: text/html

 353.  Directory listing found

Severity Low
Affects /include/db_backup (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/db_backup/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/db_backup/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:03 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 745
Connection: close
Content-Type: text/html

 354.  Directory listing found

Severity Low
Affects /include/fckeditor
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/ HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:37 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1348
Connection: close
Content-Type: text/html

 355.  Directory listing found

Severity Low
Affects /include/fckeditor (GET C=N;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/fckeditor/?C=N;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/fckeditor/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:00:50 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 1348
Connection: close
Content-Type: text/html

 356.  Directory listing found

Severity Low
Affects /include/database (GET C=S;O=D)
DetailsWe have found <TITLE>Index of
TypeInformation
DescriptionThe web server is configured to display the list of files contained in this directory. This is not recommended because the directory may contain files that are not normally exposed through links on the web site.
ImpactA user can view a list of all files from this directory possibly exposing sensitive information.
RecommendationYou should make sure the directory does not contain sensitive information or you may want to restrict directory listings from the web server configuration.
Reported by moduleText search
References
6 Tips To Secure Your Websitehttp://web.thenetter.com/web-design/6-Tips-To-Secure-Your-Website.html
Request
GET /include/database/?C=S;O=D HTTP/1.0
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Host: 192.168.0.1
Cookie: PHPSESSID=92b87a95c97a93cc5f657db8ac5c8176;ck_login_id_vtiger=1;ck_login_theme_vtiger=bluelagoon;ck_login_language_vtiger=en_us
Connection: Close
Pragma: no-cache
Referer: http://192.168.0.1:80/include/database/
Response
HTTP/1.1 200 OK
Date: Thu, 28 Sep 2006 20:01:03 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) PHP/4.3.10-16
Content-Length: 755
Connection: close
Content-Type: text/html