Test Methods ( Detailed Overview )

Here is a list of every test performed by Web Scan Service.

.NET VB File Download

Remediation Task

Remove file

WASC Classification

Information Disclosure: Information Leakage

Affected Products

This issue may affect different types of products

Technical Description

A .NET VB file contains sensitive information about the application, and may even contain usernames and passwords. By revealing such a file, an attacker can get the information he needs in order to plan further attacks, such as source code disclosure, on the server. Sample Exploit: http://[SERVER]/FILENAME.vb

Fix Recommendation

The problem is that the server's mapping is not configured correctly. Map the VB extention to the correct handler.