Summary

Netsparker detected that Apache MultiViews is enabled.

This vulnerability can be used for locating and obtaining access to some hidden resources.

Impact
An attacker can use this functionality to aid in finding hidden file processes on the directory and potentially gather further sensitive information.
Actions To Take
  1. Change your httpd.conf file. A recommended configuration for the requested directory should be in the following format:
    <Directory /{YOUR DIRECTORY}>
    	Options FollowSymLinks 
    </Directory>
    

    Remove the MultiViews option from configuration.

Classifications
WASC-14, OWASP 2013-A5 , CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C