Test Methods ( Detailed Overview )

Here is a list of every test performed by Web Scan Service.

.NET CS File Download

Remediation Task

Remove file

WASC Classification

Information Disclosure: Information Leakage

Affected Products

This issue may affect different types of products

Technical Description

A .NET CS file contains sensitive information about the application, and may even contain usernames and passwords. By revealing such a file, an attacker can get the information he needs in order to plan further attacks, such as source code disclosure, on the server. Sample Exploit: http://[SERVER]/FILENAME.cs

Fix Recommendation

The problem is that the server's mapping isn't configured correctly. Map the CS extention to the correct handler.