WebDAV

WebDAV extends HTTP with methods (PROPFIND, MKCOL, PUT, MOVE, COPY) that let clients manage files on the server, implemented by IIS WebDAV and Apache mod_dav. It is attacked by discovering it and its allowed methods, bypassing weak authentication, traversing outside its root, and, most directly, using PUT to upload an executable file.

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more