WA000-WI092 - The IIS Web site permissions 'Write' or 'Script Source' Access are selected - 'Script Source permission check'

Information

Vulnerability Key: V0013699
IA Controls: ECSC-1 Security Configuration Compliance
Categories: 2.2 Least Privilege
Severity: Category I
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 2.1
Web Site permissions to include Read, Write, and Script Source Access can be set within the IIS
Administration tool. Configuration settings made at the Web Server level are inherited by all of the Web
sites on the server. You can override inheritance by configuring the individual site or site element.
These permissions control what users can access from the web site. If Read is selected, then source
of the pages can be read, if Write is selected, then pages can be written to or updated. If the Script
Source Access is checked, source code for scripts can be viewed. This option is not available if neither
Read nor Write is selected. Allowing users access to the source of the web pages, may provide the
user with more information than they are authorized to see. This is especially an issue for the source
code for scripts on the web server.

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Windows

Control ID: ec37a1df04fd44055e5cf54be06df28fb0e6f3b790d2cc7185550f51bde4e212