|
|
Info |
Last Modified |
| 2 months ago |
|
|
|
|
Description |
RFC compliant web servers support the TRACE HTTP method, which contains a flaw that may lead to an unauthorized information disclosure. The TRACE method is used to debug web server connections and allows the client to see what is being received at the other end of the request chain. Enabled by default in all major web servers, a remote attacker may abuse the HTTP TRACE functionality, i.e. cross-site scripting (XSS), which will disclose sensitive configuration information resulting in a loss of confidentiality.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
OSVDB:
Best Practice
|
|
Solution |
If the TRACE method is not essential for your site, disable it in the web server configuration. Consult your documentation or vendor for detailed instructions on how to accomplish this.
|
|
Products |
|
Web Server
 |
All Versions |
|
|
|
|
|
|
|
Credit |
- WhiteHat Security, Inc. - WhiteHat Security, Inc.
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|