Ace of Information Disclosure II
You’ve invented a new information disclosure attack.
Threat |
|
Your HTTP response headers contain information about your host environment. An attacker can call your services or web applications with a |
|
CAPEC |
CAPEC-224 - Fingerprinting CAPEC-170 - Web Application Fingerprinting |
ASVS |
14.3.3 - Filter HTTP headers that disclose security-sensitive system information such as software/OS versions. |
CWE |
CWE-497 - Exposure of Sensitive System Information to... |