CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-284
ISO27001-A.18.1.3
OWASP 2013-A7
OWASP 2017-A3
PCI v3.2-6.5.8
WASC-2

ZSH History File Detected

Severity:
Medium
Summary

Invicti detected an exposed .zsh_history file on the target website.

Impact

.zsh_history file may contain sensitive information such as API keys, usernames, and passwords that might help an attacker to compromise the system.

Remediation

Restrict access to the .zsh_history file on your system.

Required Skills for Successful Exploitation
Actions To Take
Vulnerability Index

You can search and find all vulnerabilities

Featured resources

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding