TRACK method is enabled Security Vulnerability

Description
In the presence of other cross-domain vulnerabilities in web browsers, sensitive header information could be read from any domains that support the HTTP TRACK method. Additionally, IIS 5 does not log requests made with TRACK method.

Impact
Attackers may abuse HTTP TRACK functionality to gain access to information in HTTP headers such as cookies and authentication data.

References
W3C - RFC 2616
US-CERT VU#867593
IIS 6 WWW Service Registry Entries
Microsoft IIS Logging Failure

Acunetix Web Application Security Blog

Latest Article

Web Server Security and Database Server Security

Latest Whitepaper

Why File Upload Forms are a major security threat

Testimonials

“The issues detected were of major impact; if hackers would have found the security holes, they could have hacked an entire Joomla! Site.”

Robin Muilvijk
Quality & Testing Team, Joomla!