Skip to content

H3-2022-0069

Web Directory Listing

Category SECURITY_MISCONFIGURATION
Base Score 3.0

Description

Webservers with directory listing enabled can reveal files stored on the webserver that are not intended to be served as part of the web application.

Impact

Directory listings can enable an attacker to gain unauthorized access to sensitive information on the web server, such as source code, configuration files, keys, webserver data, and webserver backup files.

References