PCI v3.2-6.5.8
CWE-732
ISO27001-A.9.4.1
WASC-17
OWASP 2017-A6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:H/RL:O/RC:C

WebDAV Directory Has Write Permissions (IIS)

Severity:
High
Summary

Invicti detected that WebDAV is enabled on this server and this directory has write permissions enabled. Invicti was able to create a test file within this directory using the PUT method. After the test, Invicti tried to delete the file.

Impact

Malicious users may create or modify files in this directory without providing any type of authentication and they might;

  • Gain full access to the application server.

Remediation

Restrict access for method PUT or if it's not being used, consider disabling it.

Required Skills for Successful Exploitation
Actions To Take
Vulnerability Index

You can search and find all vulnerabilities

Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.