S4E just found a critical-severity finding from cve-2025-29927 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Misconfiguration·Updated Jan 20, 2026

info.cgi Environment Variable Disclosure Detection Scanner

This scanner detects the use of info.cgi Configuration Disclosure in digital assets. It exposes server environment variables like sensitive paths, internal IPs, and software versions. Detecting this helps in securing potentially leaked information.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
6.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
Detail

The info.cgi script is commonly used in various web servers to output environment variables and configuration details. It is typically utilized by system administrators and developers to troubleshoot and configure servers. The script can provide valuable details, aiding in the understanding and maintenance of server environments. However, if exposed, it can reveal sensitive details that may be exploited by attackers.

Configuration Disclosure in info.cgi can lead to the exposure of critical server environment variables. Variables such as internal IP addresses, system paths, and software versions may be inadvertently exposed. This vulnerability arises when the info.cgi script is accessible without proper access controls. Attackers can exploit this to gain insights into the server's architecture and potential weaknesses.

The technical details of this vulnerability involve accessing specific endpoints where the info.cgi file resides. Vulnerable parameters include script paths that do not correctly handle permissions or authentication checks. This exposure often manifests in URLs that return sensitive system information in response headers or body content.

When exploited, this vulnerability can lead to disclosure of sensitive data, aiding attackers in launching further attacks. Potential effects include privilege escalation, targeted attacks using disclosed information, and exploitation of revealed configurations. Mitigating this exposure is crucial for maintaining server security and preventing unauthorized access to sensitive data.

REFERENCES

Solution Advice
  • Restrict access to the info.cgi script by implementing proper access controls.
  • Regularly audit and remove unnecessary or insecure CGI scripts.
  • Ensure that environment variables are not exposed in the response body or headers.
  • Implement web server configurations that prevent unauthorized access to sensitive endpoints.
  • Educate development and operations teams about the risks of exposed environment variables.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.