Test Methods ( Detailed Overview )

Here is a list of every test performed by Web Scan Service.

Jetty CGI-BIN Arbitrary Command Execution

Remediation Task

Check server configuration

WASC Classification

Command Execution: OS Commanding

Affected Products

Jetty 4.0

Technical Description

Jetty is a Java HTTP Server and Servlet Container. A flaw in the CGIServlet allows an attacker to execute arbitrary commands on the server.

Fix Recommendation

The issue is already fixed in version 4.1.0 of Jetty.