How to solve CGI Generic Cross-Site Request Forgery Detection (potential)?

Viewed 830

"Nessus has found HTML forms on the remote web server. Some CGI scripts do not appear to be protected by random tokens, a common anti-cross-site request forgery (XSRF) protection. The web application might be vulnerable to XSRF attacks. Note that :

  • Nessus did not exploit the flaw.
  • Nessus cannot identify sensitive actions; for example, on an online bank, consulting an account is less sensitive than transferring money.

You will need to audit the source of the CGI scripts and check if they are actually affected."

"The following CGIs are not protected by a random token :

/Web Client/ListDir.htm /Web%20Client/ListDir.htm"

0 Answers
Related