8. of Information Disclosure I
An attacker can address information through a search indexer, logger, or other such mechanism.
Threat |
|
You’ve exposed some files on your web server to bots unwittingly and the contents of those files are now available in the search indexes of different search engines and their caches. They may also be available on the ”Wayback Machine.” |
|
CAPEC |
CAPEC-127 - Directory Indexing CAPEC-143 - Detect Unpublicized Web Pages CAPEC-144 - Detect Unpublicized Web Services |
ASVS |
4.1.3 - Ensure users or services only have the necessary privileges to perform the actions they need to do. |
CWE |
CWE-1230 - Exposure of Sensitive Information through Metadata CWE-524 - Use... |