Apache server-status is enabled

Description

Cytrix has detected that information regarding your Apache status is being displayed.

Sensitive information such as the Apache status is being displayed on this page, causing Information Disclosure.
Attackers can use this information to conduct further, more advanced attacks against your assets.

Severity/Score

CVSS Version 3.x – 5.3 Medium

Recommendation

If this feature is not being used by you, disable it through the Apache config file.
You can simply disable “server-status”. Also, you can restrict access to the “/server-status” URL.

References

https://cwe.mitre.org/data/definitions/200.html

https://cytrix.io/blog/blog/information-disclosure-self-revealing-our-secrets/

< Return to all Vulnerabilities

Man-In-The-Middle Attacks

Do you know these people who just push themselves into conversations?That’s Man-In-The-Middle Attacks. And from a wider angle, Man-In-The-Middle Attacks, or MITM, are built around

Read More »

The Dark Web

Let’s talk about the darker and more mysterious side of the internet, also known as The Dark Web. You’ve probably heard about it, whether it’s

Read More »