Misconfiguration of the web server has led to file list disclosure and the data is publicly available.

Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. It is dangerous to leave this function turned on for the web server because it leads to information disclosure.

Some Advice for Common Problems

  1. Configure your web server to prevent directory listings for all paths beneath the web root;
  2. Place into each directory a default file (such as index.htm) that the web server will display instead of returning a directory listing.

