VID |
22431 |
Severity |
20 |
Port |
80, ... |
Protocol |
TCP |
Class |
WWW |
Detailed Description |
The ASP.NET web server is configured to show verbose error messages. ASP.NET is a part of the Microsoft .NET framework, and a powerful tool for creating dynamic and interactive web pages. ASP.NET provides a detailed error message (such as the path under which the remote web server resides) to clients by default.
* References: http://msdn2.microsoft.com/en-us/library/ms954599.aspx
* Platforms Affected: Microsoft .NET Framework Any version Microsoft Windows Any version |
Recommendation |
Configure your web server such as the option 'customErrors mode' is set to 'On' instead of 'Off', by refering to the following web sites: http://www.15seconds.com/issue/030102.htm http://msdn2.microsoft.com/en-us/library/ms954599.aspx |
Related URL |
(CVE) |
Related URL |
(SecurityFocus) |
Related URL |
(ISS) |
|