Trace.axd Information Leak

Deprecated: 2020-02-11

No longer widely supported by browsers.

Type: Active Scan

Risk: Medium

Description

The ASP.NET Trace Viewer (trace.axd) was found to be available. This component can leak a significant amount of valuable information.

Solution

Consider whether or not Trace Viewer is actually required in production, if it isn't then disable it. If it is then ensure access to it requires authentication and authorization.

References

CWE: 215

WASC: 13

Code

Last updated: 2020-04-30 09:48:11.442Z