Test Methods ( Detailed Overview )

Here is a list of every test performed by Web Scan Service.

HTTP TRACK Method Cross-Site Scripting

Remediation Task

Disable unnecessary components

WASC Classification

Client-side Attacks: Cross-site Scripting

Affected Products

Microsoft IIS / Potentially possibly on Apache

Technical Description

HTTP TRACK is enabled on the web server. HTTP TRACK request method allows that the data received by the server is sent back to the client. The TRACK method could be used from a malicious user to start a Cross-Site scripting attack.

Fix Recommendation

This problem has to be solved in the configuration of the web server: Deactivate TRACK Method.