Download Netsparker
Pricing
Blog
Contact
Netsparker

Apache MultiViews Enabled

Netsparker detected that Apache MultiViews is enabled.

This vulnerability can be used for locating and obtaining access to some hidden resources.

Impact

An attacker can use this functionality to aid in finding hidden file processes on the directory and potentially gather further sensitive information.

Actions to Take

  1. Change your httpd.conf file. A recommended configuration for the requested directory should be in the following format:
    <Directory /{YOUR DIRECTORY}>
    	Options FollowSymLinks 
    </Directory>
    

    Remove the MultiViews option from configuration.


Go back to the Complete list of Vulnerability Checks.