Vulnerabilities/

Apache server-status enabled

Impact: Medium

Description

Sensitive information is exposed on this page. Attackers can use this information to extend their attack.

Recommendation

Disable server-status in the Apache config file. Another mitigation is to limit access to /server-status URL.

References

Last updated on February 15, 2021

Use SmartScanner Free version to test for this issue

Download