Summary #

Invicti detected that WebDAV is enabled on this server and this directory has write permissions enabled. Invicti was able to create a test file within this directory using the PUT method. After the test, Invicti tried to delete the file.

Impact #
Malicious users may create or modify files in this directory without providing any type of authentication and they might;
  • Gain full access to the application server.
Remediation #
Restrict access for method PUT or if it's not being used, consider disabling it.
Classifications #
PCI v3.1-6.5.8; PCI v3.2-6.5.8; CWE-732; ISO27001-A.9.4.1; WASC-17; OWASP 2017-A6 , CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:H/RL:O/RC:C
Vulnerability Index

Vulnerability Index

You can search and find all vulnerabilities


Search Vulnerability


Dead accurate, fast & easy-to-use Web Application Security Scanner

Get a demo