The first step is confirming WebDAV and learning what it allows. An OPTIONS request returns the DAV header and the Allow list of methods, and PROPFIND lists resources. Tools then probe which extensions can be uploaded and executed in each writable directory, which determines whether the server is exploitable through PUT.
curl -s -X OPTIONS http://<target>/ -i | grep -iE 'DAV|Allow'
curl -s -X PROPFIND http://<target>/ -H 'Depth: 1' --data '' # list resources
davtest -url http://<target>/ # test uploadable/executable types
Exploitation notes#
- The
Allowheader reveals whether PUT, MOVE, DELETE, and MKCOL are available, shaping the attack. davtestreports which file types upload successfully and which then execute, directly flagging the RCE path.- A directory that accepts PUT is the target for PUT upload to RCE; MOVE can rename a disallowed extension to an executable one.