CWE-548: Exposure of Information Through Directory Listing
The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.
How it's found
Exposure of Information Through Directory Listing is a specific, narrowly defined instance of a broader pattern. Testers confirm it with targeted code review and a proof-of-concept input that exercises the exact code path this weakness describes.
Consequences
- Read Files or Directories: Exposing the contents of a directory can lead to an attacker gaining access to source code or providing useful information for the attacker to devise exploits, such as creation times of files or any information that may be encoded in file names. The directory listing may also compromise private or confidential data.
Mitigations
- Architecture and Design/System Configuration: Recommendations include restricting access to important directories or files by adopting a need to know requirement for both the document and server root, and turning off features such as Automatic Directory Listings that could expose private files and provide information that could be utilized by an attacker when formulating or conducting an attack.
How TurboPentest tests for this
TurboPentest's automated black-box pentest actively probes for Exposure of Information Through Directory Listing using Nikto and Nuclei, which check the live target for directory browsing left enabled on the web server, with no source code required.
Tools: Nikto, Nuclei
Frequently asked questions
What is CWE-548?
The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.
How do you find Exposure of Information Through Directory Listing?
Exposure of Information Through Directory Listing is a specific, narrowly defined instance of a broader pattern. Testers confirm it with targeted code review and a proof-of-concept input that exercises the exact code path this weakness describes.
What is the impact of CWE-548?
Read Files or Directories: Exposing the contents of a directory can lead to an attacker gaining access to source code or providing useful information for the attacker to devise exploits, such as creation times of files or any information that may be encoded in file names. The directory listing may also compromise private or confidential data.
Does TurboPentest test for Exposure of Information Through Directory Listing?
TurboPentest's automated black-box pentest actively probes for Exposure of Information Through Directory Listing using Nikto and Nuclei, which check the live target for directory browsing left enabled on the web server, with no source code required.
Related CWEs
- Base weaknessCWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
- Base weaknessCWE-209: Generation of Error Message Containing Sensitive Information
- Base weaknessCWE-215: Insertion of Sensitive Information Into Debugging Code
- Variant weaknessCWE-219: Storage of File with Sensitive Data Under Web Root
- Base weaknessCWE-295: Improper Certificate Validation
- Base weaknessCWE-459: Incomplete Cleanup
Written and reviewed by
Michel Chamberland - Founder & CEO, IntegSec
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security
Michel has spent 20+ years on offensive security teams including IBM X-Force Red and Trustwave SpiderLabs, leading penetration tests, red team engagements, and breach response for Fortune 500 customers. He is the founder of IntegSec and the architect of TurboPentest.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest