WA000-WI090 - Directory Browsing is not disabled.

Information

Vulnerability Key: V0006755
IA Controls: ECSC-1 Security Configuration Compliance
Categories: 2.2 Least Privilege
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 2.1, Guide to the Secure Configuration and Administration of
Micorosoft Internet Information
This ensures that your directory structure, filenames, and web publishing features are not accessible.
Such information and the contents of files listed are normally readable by the anonymous web user,
yet are not intended to be viewed as they often contain information relevant to the configuration and
security of the web service. The Directory Browsing feature can be used to facilitate a directory
traversal and subsequent directory traversal exploits.

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1

Plugin: Windows

Control ID: 244d67411197148e36286c18390a1415b6391cf69ed3fe931e7656bbd2e38a6e