H3-2022-0069
Web Directory Listing
Category | SECURITY_MISCONFIGURATION |
Base Score | 3.0 |
Description
Webservers with directory listing enabled can reveal files stored on the webserver that are not intended to be served as part of the web application.
Impact
Directory listings can enable an attacker to gain unauthorized access to sensitive information on the web server, such as source code, configuration files, keys, webserver data, and webserver backup files.