Vulnerability Name
Classifications
Severity
Elmah.axd / Errorlog.axd Detected
PCI v3.2-6.5.6, CAPEC-347, CWE-16, HIPAA-164.306(a), 164.308(a), ISO27001-A.18.1.3, WASC-15, OWASP 2013-A5, OWASP 2017-A6, CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C
High
Trace.axd Detected
PCI v3.2-6.5.6, CAPEC-347, CWE-16, HIPAA-164.306(a), 164.308(a), ISO27001-A.18.1.3, WASC-15, OWASP 2013-A5, OWASP 2017-A6, CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C
High
ASP.NET Cookieless Authentication Is Enabled
CWE-16, OWASP 2013-A5, OWASP 2017-A6
Medium
ASP.NET CustomErrors Is Disabled
CWE-16, OWASP 2013-A6, OWASP 2017-A3
Medium
ASP.NET Cookieless Session State Is Enabled
CWE-16, OWASP 2013-A5, OWASP 2017-A6
Medium
ASP.NET: Failure To Require SSL For Authentication Cookies
CWE-16, OWASP 2017-A6
Medium
ASP.NET ValidateRequest Is Globally Disabled
CWE-16, OWASP 2013-A5, OWASP 2017-A6
Medium
Apache Server-Info Detected
CAPEC-347, CWE-16, ISO27001-A.18.1.3, WASC-14, OWASP 2013-A5, OWASP 2017-A6, CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
Medium
Apache Server-Status Detected
CAPEC-347, CWE-16, ISO27001-A.18.1.3, WASC-14, OWASP 2013-A5, OWASP 2017-A6, CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C
Medium
Axis system configuration listing enabled in WEB-INF/server-config.wsdd
CWE-16, OWASP 2013-A5, OWASP 2017-A6, CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
Medium
Axis Development Mode Enabled in WEB-INF/server-config.wsdd
CWE-16, OWASP 2013-A5, OWASP 2017-A6, CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
Medium
Custom Error Pages Are Not Configured in WEB-INF/web.xml
CWE-16, OWASP 2013-A5, OWASP 2017-A6, CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
Medium