Summary #

Netsparker identified a stack trace disclosure (Python) in the target web server's HTTP response.

Impact #
An attacker can obtain information such as:
  • Stack trace.
  • Physical file paths of relevant files.
  • Information about the generated exception.
This information might help an attacker gain more information and potentially focus on the development of further attacks for the target system.
Remediation #
Configure your application not to provide detailed error pages in production environments. Save all information regarding the error to a backend storage, such as a log or a text file, and show a friendly custom error page to the user.
Classifications #
PCI v3.1-6.5.5, PCI v3.2-6.5.5, CAPEC-214, CWE-248, HIPAA-248, ISO27001-A.18.1.3, WASC-14, OWASP 2013-A5, OWASP 2017-A6 , CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Index

Vulnerability Index

You can search and find all vulnerabilities

OR

Search Vulnerability

Netsparker

Dead accurate, fast & easy-to-use Web Application Security Scanner

GET A DEMO