QID 150672
Date Published: 2023-04-27
QID 150672: WebDAV Detected
WebDAV (Web Distributed Authoring and Versioning) is an extension of the HTTP protocol that enables users to edit and manage files on a web server.
Enabling WebDAV can potentially expose sensitive files and folders on a web server, allowing unauthorized access or modification by malicious actors.
WebDAV can be exploited by attackers for various types of attacks, including: enumeration to gather information about files and folders, injection attacks to insert malicious code, file manipulation to modify or download files, and denial-of-service attacks to disrupt server operations.
QID Detection Logic (Unauthenticated) :
This QID uses an HTTP OPTIONS request to verify if the web server is vulnerable by analyzing the response.
Enabling WebDAV without proper security measures can lead to unauthorized access, data modification or destruction.
CVEs related to QID 150672
| Advisory ID | Software | Component | Link |
|---|