Summary

Acunetix 360 detected that WebDAV is enabled on this server and this directory has write permissions enabled. Acunetix 360 was able to create a test file within this directory using the PUT method. After the test, Acunetix 360 tried to delete the file.

Impact

Malicious users may create or modify files in this directory without providing any type of authentication and they might;
  • Gain full access to the application server.

Remediation

Restrict access for method PUT or if it's not being used, consider disabling it.

Severity

High

Classification

PCI v3.2-6.5.8 CWE-732 ISO27001-A.9.4.1 WASC-17 OWASP 2017-A6 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:H/RL:O/RC:C