WG205 - The web document (home) directory is not in a separate partition from the web servers system files.

Information

Vulnerability Key: V0003333
IA Controls: DCPA-1 Partitioning the Application
Categories: 2.2 Least Privilege
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 3.10, Web Site Administration Policies & Procedures, With Amendments
and Corrections incorporated in red italics
Web content is accessible to the anonymous web user. For such an account to have access to system
files of any type is a major security risk that is entirely avoidable. To obtain such access is the goal of
directory traversal and URL manipulation vulnerabilities. To facilitate such access by mis-configuring
the web document (home) directory is a serious error. In addition, having the path on the same drive
as the system folder compounds potential attacks such as drive space exhaustion.
NOTE: Review each site's path to ensure it is not on the same partition as the system files or a child of the web application's directory.

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1

Plugin: Windows

Control ID: e3102179674a88c9160213571c14608bceafcc82d631e606f271a269f9ea59a0