This script is Copyright (C) 2007-2010 Tenable Network Security, Inc.
Family
Web Servers
Nessus Plugin ID
24244 (dotnet_framework_custom_errors.nasl)
Bugtraq ID
CVE ID
Description:
Synopsis :
The remote ASP.NET web server does not have custom errors set
Description :
The remote ASP.NET web server is configured to show verbose error messages, which might lead into the disclosure of potential sensitive information about the remote installation (such as the path under which the remote web server resides) or about the remote ASP.NET applications.
Solution :
Configure your server such as the option 'customErrors mode' is set to 'On' instead of 'Off'
Risk factor :
Medium / CVSS Base Score : 4.3 (CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)