Details
Alert ID 10033
Alert Type Passive
Status release
Risk Medium
CWE 548
WASC 16
Technologies Targeted All
Tags CWE-548
OWASP_2017_A06
OWASP_2021_A05
More Info Scan Rule Help

Summary

It is possible to view a listing of the directory contents. Directory listings may reveal hidden scripts, include files, backup source files, etc., which can be accessed to reveal sensitive information.

Solution

Configure the web server to disable directory browsing.

Other Info

Web server identified: Apache 2

References

Code

org/zaproxy/zap/extension/pscanrules/DirectoryBrowsingScanRule.java