Summary #

Netsparker identified a version disclosure (ASP.NET MVC framework) in target web server's HTTP response.

This information can help an attacker gain a greater understanding of the systems in use and potentially develop further attacks targeted at the specific version of ASP.NET MVC framework.

Impact #
An attacker might use the disclosed information to harvest specific security vulnerabilities for the version identified.
Remediation #
Configure your web server to prevent information leakage from the X-AspNetMvc-Version header of its HTTP response by adding the following code to the Application_Start() function in Global.asax.cs:
	MvcHandler.DisableMvcResponseHeader = true;
Classifications #
CAPEC-170, CWE-205, HIPAA-205, ISO27001-A.18.1.3, WASC-45, OWASP 2013-A5, OWASP 2017-A6
Vulnerability Index

Vulnerability Index

You can search and find all vulnerabilities

OR

Search Vulnerability

Netsparker

Dead accurate, fast & easy-to-use Web Application Security Scanner

GET A DEMO