Loading HuntDB...

Nginx server version disclosure on engineeringblog

None
Y
Yelp
Submitted None
Reported by japz

Vulnerability Details

Technical details and impact analysis

Information Disclosure
Hi Yelp Team, I have found a little information disclosure on your system with regards to the version of server you are using, due to not properly handling 404 errors , whe you go to the page that i not existing, the exact nginx version was disclosed. __PoC URL:__ engineeringblog.yelp.com/test __PoC Screenshot:__ {F33044} It is important to keep secret of the exact server versions. __Mitigation:__ You may want to create a customize 404 error page, or you can just simply remove the nginx server version. Regards Japz

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted

Weakness

Information Disclosure