The following resources may be vulnerable to SSI injection (on HTTP headers) : /manual/howto/ssi.html
Issue
- Security scanning with Nessus tool reports ssi.html to be vulnerable to SSI injection.
- Remote web server hosts one or more CGI scripts that fail to adequately sanitize.
Environment
- Red Hat Enterprise Linux 8
- Apache httpd 2.4
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.