CWE-16
ISO27001-A.9.4.1
WASC-14
OWASP 2013-A5
OWASP 2017-A6

Apache Multiple Choices Enabled

Severity:
Low
Summary

Invicti detected that Apache Multiple Choices is enabled.

This vulnerability can be used for locating and obtaining access to some hidden resources.

Impact

An attacker can use this functionality to aid in finding hidden files in the site and potentially gather further sensitive information.

Remediation
Required Skills for Successful Exploitation
Actions To Take
  1. Change your server configuration file to disable spelling module. A recommended configuration for the requested directory should be in the following format:
  2. <Directory /{YOUR DIRECTORY}> CheckSpelling Off </Directory>
Vulnerability Index

You can search and find all vulnerabilities

Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.