Test Methods ( Detailed Overview )

Here is a list of every test performed by Web Scan Service.

HTTP TRACE Method Cross-Site Scripting

Remediation Task

Disable unnecessary components

WASC Classification

Client-side Attacks: Cross-site Scripting

Affected Products

This issue may affect different types of products

Technical Description

HTTP TRACE is enabled on the web server. HTTP TRACE request method allows that the data received by the server is sent back to the client. The TRACE method could be used from a malicious user to start a Cross-Site scripting attack.

Fix Recommendation

This problem has to be solved in the configuration of the web server: Deactivate Trace Method.