Description
Apache /server-status displays information about your Apache status. If you are not using this feature, disable it.
Remediation
Disable this functionality if not required. Comment out the <Location /server-status> section from httpd.conf.
References
Related Vulnerabilities
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-0195)
Zend framework configuration file information disclosure
WordPress Plugin BackupBuddy Information Disclosure (2.2.28)
TYPO3 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-3664)