WA000-WI6096 - The UrlSegmentMaxCount registry entry is not set properly.

Information

Vulnerability Key: V0013722
IA Controls: ECSC-1 Security Configuration Compliance
Categories: 2.2 Least Privilege
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 2.1
The UrlSegmentMaxCount value determines the maximum number of URL path segments accepted by the server. It effectively limits the
number of slashes that can be included by the user in a requested URL. It is recommended that one set fairly stringent limits on this
value based on the depth of the webdocument root tree to protect the server from a file system traversal attack. The default value
for this key is 255.

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5

Plugin: Windows

Control ID: 31811b1de8ea69cb202277e31d320c7b52a9d3fe909b54bb16845d166c9cbcee