Mitch,
I am having the same problem. Here is the error I received from security metrics.
Description: Web Application Information Disclosure Synoposis: The remote web application discloses path information. Impact: At least one web application hosted on the remote web server discloses the physical path to its directories when a malformed request is sent to it. Leaking this kind of information may help an attacker fine-tune attacks against the application and its backend. Data Received: The request POST /default.aspx HTTP/1.1\r Host: www.practicepointhiv.com\r Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r Accept-Language: en\r Content-Type: application/x-www-form-urlencoded\r Connection: Keep-Alive\r Content- Length: 79\r User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)\r Pragma: no-cache\r Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*\r \r dnn$ctr512 $DNNArticle_List$MyArticleList$MyPageNav$dlPages=default.aspx%00.html produces the following path information : <span id="dnn_dnnCopyright_lblCopyright" class="FooterLinks">Copyr [...] <a id="dnn_dnnTerms_hypTerms" class="FooterLinks" rel="nofollow" href="h ttp://www .practicepointhiv.com/Home/tabid/38/ctl/Terms/Default.aspx">Ter ms Of Use</a> <a id="dnn_dnnPrivacy_hypPrivacy" class="FooterLinks" rel="nofollo [...] </div> The request POST /Home/tabid/38/ctl/Privacy/Default.aspx HTTP/1.1\r Host: www.practicepointhiv.com\r Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r Accept-Language: en\r Content-Type: application/x-www-form-urlencoded\r Connection: Keep-Alive\r Content- Length: 44\r User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)\r Pragma: no-cache\r Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*\r \r dnn$dnnSearch$txtSearch=Default.aspx%00.html produces the following path information : <body id="Body"> <form name="Form" method="post" action="/Home/tabid/38/ctl/Privacy/Defau lt.aspx" id="Form" enctype="multipart/form-data"> <div> <input type="hidden" name="StylesheetManager_TSSM" id="StylesheetM [...] The request POST /Home/tabid/38/ctl/Terms/Default.aspx HTTP/1.1\r Host: www.practicepointhiv.com\r Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r Accept-Language: en\r Content-Type: application/x-www-form-urlencoded\r Connection: Keep-Alive\r Content- Length: 44\r User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)\r Pragma: no-cache\r Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*\r \r dnn$dnnSearch$txtSearch=Default.aspx%00.html produces the following path information : <body id="Body"> <form name="Form" method="post" action="/Home/tabid/38/ctl/Terms/Default .aspx" id="Form" enctype="multipart/form-data"> <div> <input type="hidden" name="StylesheetManager_TSSM" id="StylesheetM [...] The request POST /Default.aspx HTTP/1.1\r Host: www.practicepointhiv.com\r Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r Accept-Language: en\r Content-Type: application/x-www-form-urlencoded\r Connection: Keep-Alive\r Content- Length: 79\r User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)\r Pragma: no-cache\r Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*\r \r dnn$ctr512 $DNNArticle_List$MyArticleList$MyPageNav$dlPages=Default.aspx%00.html produces the following path information : <span id="dnn_dnnCopyright_lblCopyright" class="FooterLinks">Copyr [...] <a id="dnn_dnnTerms_hypTerms" class="FooterLinks" rel="nofollow" href="h ttp://www .practicepointhiv.com/Home/tabid/38/ctl/Terms/Default.aspx">Ter ms Of Use</a> <a id="dnn_dnnPrivacy_hypPrivacy" class="FooterLinks" rel="nofollo [...] </div> The request POST /Home.aspx HTTP/1.1\r Host: www.practicepointhiv.com\r Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1\r Accept-Language: en\r Content-Type: application/x-www-form-urlencoded\r Connection: Keep-Alive\r Content- Length: 76\r User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)\r Pragma: no-cache\r Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*\r \r dnn$ctr512 $DNNArticle_List$MyArticleList$MyPageNav$dlPages=Home.aspx%00.html produces the following path information : <span id="dnn_dnnCopyright_lblCopyright" class="FooterLinks">Copyr [...] <a id="dnn_dnnTerms_hypTerms" class="FooterLinks" rel="nofollow" href="h ttp://www .practicepointhiv.com/Home/tabid/38/ctl/Terms/Default.aspx">Ter ms Of Use</a> <a id="dnn_dnnPrivacy_hypPrivacy" class="FooterLinks" rel="nofollo [...] </div> Resolution: Filter error messages containing path information.Risk Factor: Medium/ CVSS2 Base Score: 5.0 AV:N/AC:L/Au:N/C:P/I:N/A:N