Falhas do tipo CWE-548

60 resultados

Exposição de Informações por Listagem de Diretório

Ocorre quando o servidor web lista o conteúdo de um diretório automaticamente, exibindo arquivos e pastas quando não há um arquivo índice (como index.html). Um atacante acessa uma URL de diretório e vê todos os arquivos disponíveis, podendo descobrir backups, arquivos de configuração, código-fonte ou outros ativos sensíveis não intencionados para exposição pública.

Exemplo

Um desenvolvedor carrega assets em /app/resources/ mas esquece de criar um index.html. Ao acessar https://exemplo.com/app/resources/, o servidor Apache com autoindex ativado lista todos os arquivos: backup.sql, config.json com credenciais, e versões antigas do código — tudo visível para qualquer um.

Como mitigar

Desative a listagem automática de diretórios no servidor (DirectoryIndex desativado no Apache, autoindex off, ou equivalente no Nginx). Coloque um index.html ou index.php em cada diretório público, ou restrinja acesso via permissões de arquivo e regras de firewall. Valide regularmente com varreduras que tentam acessar diretórios conhecidos.

CVE-2021-32515MEDIUMQSAN Storage Manager - Exposure of Information Through Directory ListingEPSS 0.8%CVE-2024-7809MEDIUMSourceCodester Online Graduate Tracer System nbproject exposure of information through directory listingEPSS 0.8%CVE-2022-36243MEDIUMDirectory Traversal on Shop Beat ServicesEPSS 0.7%CVE-2016-15019MEDIUMtombh jekbox server.rb exposure of information through directory listingEPSS 0.7%CVE-2023-49979HIGHA directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the applicatEPSS 0.7%CVE-2014-125069MEDIUMsaxman maps-js-icoads exposure of information through directory listingEPSS 0.7%CVE-2023-51948HIGHA Site-wide directory listing vulnerability in /fm in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to list the files hostEPSS 0.7%CVE-2025-2651MEDIUMSourceCodester Online Eyewear Shop admin exposure of information through directory listingEPSS 0.7%CVE-2025-2652MEDIUMSourceCodester Employee and Visitor Gate Pass Logging System exposure of information through directory listingEPSS 0.7%CVE-2026-22860HIGHRack has a Directory Traversal via Rack:DirectoryEPSS 0.7%CVE-2024-42007MEDIUMSPX (aka php-spx) through 0.4.15 allows SPX_UI_URI Directory Traversal to read arbitrary files.EPSS 0.6%CVE-2024-22082HIGHAn issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated directory listing can occur: the wEPSS 0.6%CVE-2025-2038MEDIUMcode-projects Blood Bank Management System upload exposure of information through directory listingEPSS 0.6%CVE-2025-61685MEDIUMMastra Docs MCP Server `@mastra/mcp-docs-server` Leads to Information ExposureEPSS 0.6%CVE-2021-47718HIGHOpenBMCS Directory Listing Information DisclosureEPSS 0.5%CVE-2025-4909MEDIUMSourceCodester Client Database Management System exposure of information through directory listingEPSS 0.5%CVE-2024-3707MEDIUMExposure of Information Through Directory Listing vulnerability in OpenGnsysEPSS 0.5%CVE-2025-13200MEDIUMSourceCodester Farm Management System exposure of information through directory listingEPSS 0.4%CVE-2021-45446MEDIUM Pentaho Business Analytics Server - Exposure of Information Through Directory ListingEPSS 0.4%CVE-2020-36921MEDIUMRED-V Super Digital Signage System 5.1.1 Log Information Disclosure VulnerabilityEPSS 0.4%