Summary #

Netsparker identified a Directory Listing (WebDAV).

The web server responded with a list of files located in the target directory.

Impact #
An attacker can see the files located in the directory and could potentially access files which disclose sensitive information.
Actions To Take #
  1. Configure the web server to disallow directory listing requests.
  2. If you are not using this extension, it's recommended to be disabled.
Classifications #
CAPEC-127, CWE-548, ISO27001-A.9.4.1, WASC-16, OWASP PC-C6, OWASP 2013-A5, OWASP 2017-A6 , CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Index

Vulnerability Index

You can search and find all vulnerabilities

OR

Search Vulnerability

Netsparker

Dead accurate, fast & easy-to-use Web Application Security Scanner

GET A DEMO