CWE一覧に戻る
CWE-548

名簿掲載による情報露出

Exposure of Information Through Directory Listing
脆弱性 レビュー中
JA

この製品は、ディレクトリ内にあるすべてのリソースのインデックスを含むディレクトリリストを不適切に公開しています。

EN

The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Scope: Confidentiality / Impact: Read Files or Directories
Recommendations include restricting access to important directories or files by adopting a need to know requirement for both the document and server root, and turning off features such as Automatic Directory Listings that could expose private files and provide information that could be utilized by an attacker when formulating or conducting an attack.
MITRE公式ページ — CWE-548