Microsoft ASP.NET Application Tracing trace.axd Information Disclosure

medium Nessus Plugin ID 10993

Synopsis

The remote host is affected by an information disclosure vulnerability.

Description

The ASP.NET web application running in the root directory of the remote web server has application tracing enabled. This allows an unauthenticated, remote attacker to view the last 50 web requests made to the server, including sensitive information like Session ID values and the physical path to the requested file.

Solution

Set <trace enabled=false> in web.config

Plugin Details

Severity: Medium

ID: 10993

File Name: DDI_IIS_dotNet_Trace.nasl

Version: 1.24

Type: remote

Family: CGI abuses

Published: 6/5/2002

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: cpe:/a:microsoft:asp.net

Vulnerability Publication Date: 1/1/2002