Download Netsparker
Pricing
Blog
Contact
Netsparker

Code Execution via WebDAV Detected on Target Web Application

Netsparker identified that code execution via WebDAV. {PRODUCT} successfully uploaded a file via PUT method and then renamed this file via MOVE method. When requesting the file, code is executed in the context of the web server. At the end of the attack, Netsparker tried to delete the file.

Impact

An attacker can execute malicious code by abusing the Code Execution via WebDAV vulnerability on the server.

Required Skills for Successful Exploitation

This vulnerability is not difficult to leverage. Successful exploitation requires knowledge of the programming language, access to or the ability to produce source code for use in such attacks, and minimal attack skills.

Remedy

Remove write permissions from this directory or disable WebDAV if it's not being used.

Go back to the Complete list of Vulnerability Checks.