Korean
<< Back
VID 22431
Severity 20
Port 80, ...
Protocol TCP
Class WWW
Detailed Description The ASP.NET web server is configured to show verbose error messages. ASP.NET is a part of the Microsoft .NET framework, and a powerful tool for creating dynamic and interactive web pages. ASP.NET provides a detailed error message (such as the path under which the remote web server resides) to clients by default.

* References:
http://msdn2.microsoft.com/en-us/library/ms954599.aspx

* Platforms Affected:
Microsoft .NET Framework Any version
Microsoft Windows Any version
Recommendation Configure your web server such as the option 'customErrors mode' is set to 'On' instead of 'Off', by refering to the following web sites:
http://www.15seconds.com/issue/030102.htm
http://msdn2.microsoft.com/en-us/library/ms954599.aspx
Related URL (CVE)
Related URL (SecurityFocus)
Related URL (ISS)