Summary
Acunetix 360 identified a stack trace disclosure (ASP.NET) in the target web server's HTTP response.
Impact
An attacker can obtain information such as:
- ASP.NET version.
- Physical file path of temporary ASP.NET files.
- Information about the generated exception and possibly source code, SQL queries, etc.
Remediation
Apply following changes on your
web.config file to prevent information leakage by applying custom error pages. <System.Web>
<customErrors mode="On" defaultRedirect="~/error/GeneralError.aspx">
<error statusCode="403" redirect="~/error/Forbidden.aspx" />
<error statusCode="404" redirect="~/error/PageNotFound.aspx" />
<error statusCode="500" redirect="~/error/InternalError.aspx" />
</customErrors>
</System.Web>