A PCI scanner of a client is current showing a potential path traversal exploit. The document root is set to /home/somefolder/somewebfoldername/
YET, visiting ourwebsite.com/manual shows the Apache manual. The same goes for ourwebsite.com:8443/manual
The exploit highlighted is: ourwebsite.com/manual/howto/ssi.html?..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F/etc/passwd%00
I don't see exactly how this would display the contents of passwd, but my actual questions are two fold:
1) Would deleting the contents of the manual folder solve this? and 2) Is this just masking a larger problem? I thought that apache could never reach outside of the DocumentRoot?
TIA
However, it appears that this was indeed a false positive - No passwords were outputted, and instead the scanner saw the output the Apache manual as a method of path traversal.
– flukeflume Apr 03 '14 at 16:19