Summary #

Netsparker detected that WebDAV is enabled on this server and this directory has write permissions enabled. Netsparker was able to create a test file within this directory using the PUT method. After the test, Netsparker tried to delete the file.

Impact #
Malicious users may create or modify files in this directory without providing any type of authentication and they might;
  • Gain full access to the application server.
Remediation #
Restrict access for method PUT or if it's not being used, consider disabling it.
Classifications #
PCI v3.1-6.5.8, PCI v3.2-6.5.8, CWE-732, ISO27001-A.9.4.1, WASC-17, OWASP 2017-A6 , CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:H/RL:O/RC:C
Vulnerability Index

Vulnerability Index

You can search and find all vulnerabilities

OR

Search Vulnerability

Netsparker

Dead accurate, fast & easy-to-use Web Application Security Scanner

GET A DEMO