Skip to main content
CUI

Vulnerability V-218781

Back

V-218781

CAT II

Backup interactive scripts on the IIS 10.0 server must be removed.

Ships Affected
2
Total Findings
4
Open
0
Closed
0

Check Text

If the website does not utilize CGI, this finding is Not Applicable. Open the IIS 10.0 Manager. Right-click the IIS 10.0 web site name and select "Explore". Search for the listed script extensions Search for the following files: *.bak, *.old, *.temp, *.tmp, *.backup, or “copy of...”. If files with these extensions are found, this is a finding.

Fix Text

Remove the backup files from the production web server.

STIG Reference

STIG
Microsoft IIS 10.0 Site Security Technical Implementation Guide
Version
2
Release
15
Rule ID
SV-218781r1022700_rule

All Occurrences

This vulnerability appears on 2 ship(s)

Ship Hull # Source File Status Assigned To Scan Date Actions
LAB BASELINES BASELINE SCHR-P3-DP-001_IIS10Site_Default_Web_Site_V2R14_20260305-133115.cklb
Unassigned 2026-03-12T15:38:14.459023 View in Context
USNS MONTFORD POINT T-ESD-1 _Reviewed/MONT-DP-001/Checklist/MONT-DP-001_IIS10Site_Default_Web_Site_V2R12_20251023-143912.ckl
Unassigned 2026-01-14T12:57:35.375369 View in Context
USNS MONTFORD POINT T-ESD-1 _Reviewed/MONT-MB-002/Checklist/MONT-MB-002_IIS10Site_Exchange_Back_End_V2R12_20251023-152602.ckl
Unassigned 2026-01-14T12:57:33.300070 View in Context
USNS MONTFORD POINT T-ESD-1 _Reviewed/MONT-MB-002/Checklist/MONT-MB-002_IIS10Site_Default_Web_Site_V2R12_20251023-152518.ckl
Unassigned 2026-01-14T12:57:33.098574 View in Context
CUI