OSVDB ID: 877

Title: Multiple Web Server Dangerous HTTP Method TRACE

Info

Disclosure

Jan 20, 2003

Discovery

Unknown

Dates

Exploit

Jan 20, 2003

Solution

Unknown

Description

RFC compliant web servers support the TRACE HTTP method, which contains a flaw that may lead to an unauthorized information disclosure. The TRACE method is used to debug web server connections and allows the client to see what is being received at the other end of the request chain. Enabled by default in all major web servers, a remote attacker may abuse the HTTP TRACE functionality, i.e. cross-site scripting (XSS), which will disclose sensitive configuration information resulting in a loss of confidentiality.

Classification

Location: Remote / Network Access
Attack Type: Information Disclosure
Impact: Loss of Confidentiality
Exploit: Exploit Public
Disclosure: OSVDB Verified
OSVDB: Web Related

Solution

If the TRACE method is not essential for your site, disable it in the web server configuration. Consult your documentation or vendor for detailed instructions on how to accomplish this.

Products

All Vendors

Web Server

All Versions

References

Credit

  • WhiteHat Security, Inc. - WhiteHat Security, Inc.


Direct URL: http://osvdb.org/877