SV-28849r1_rule
V-2229
WG410
WG410 W22
CAT II
10
Ensure the CGI scripts are owned by root, the service account running the web service, the web author or the SA, and that the anonymous web user account has Read Only or Read - Execute permissions to such scripts.
Query the SA to determine if CGI scripts are used as part of the web site.
If interactive scripts are being used, check the permissions of these files to ensure they meet the following permissions:
interactive script files
Administrators Full Control
WebManagers Modify
System Read/Execute
Webserver Account Read/Execute
If the interactive scripts do not meet the above permissions or are less restrictive, this is a finding.
V-2229
False
WG410 W22
Query the SA to determine if CGI scripts are used as part of the web site.
If interactive scripts are being used, check the permissions of these files to ensure they meet the following permissions:
interactive script files
Administrators Full Control
WebManagers Modify
System Read/Execute
Webserver Account Read/Execute
If the interactive scripts do not meet the above permissions or are less restrictive, this is a finding.
M
Web Administrator
161