Description
Apache /server-status displays information about your Apache status. If you are not using this feature, disable it.
Remediation
Disable this functionality if not required. Comment out the <Location /server-status> section from httpd.conf.
References
Related Vulnerabilities
WordPress Plugin Thinkun Remind 'dirPath' Parameter Information Disclosure (1.1.3)
ASP.NET login credentials stored in plain text
WordPress Plugin Timetable and Event Schedule by MotoPress Information Disclosure (2.3.19)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-4721)