VYPR

CWE-548

Exposure of Information Through Directory Listing

VariantDraft

Description

The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (60)

page 3 of 3
  • CVE-2025-27452MedJul 3, 2025
    risk 0.34cvss 5.3epss 0.00

    The configuration of the Apache httpd webserver which serves the MEAC300-FNADE4 web application, is partly insecure. There are modules activated that are not required for the operation of the FNADE4 web application. The functionality of the some modules pose a risk to the…

  • CVE-2025-45320MedMay 5, 2025
    risk 0.34cvss 5.3epss 0.00

    A Directory Listing Vulnerability was found in the /osms/Requester/ directory of the Kashipara Online Service Management Portal V1.0.

  • CVE-2024-3707MedApr 12, 2024
    risk 0.34cvss 5.3epss 0.00

    Information exposure vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to enumerate all files in the web tree by accessing a php file.

  • CVE-2021-45446MedNov 2, 2022
    risk 0.33cvss 5.0epss 0.00

    A vulnerability in Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not cascade the hidden property to the children of the Home folder.  This directory listing provides an attacker with the complete index of all the resources…

  • CVE-2026-82778MedSep 14, 2026
    risk 0.28cvss 4.3epss 0.00

    An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.

  • CVE-2026-82775MedSep 14, 2026
    risk 0.28cvss 4.3epss 0.00

    An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.

  • CVE-2025-2827MedJul 8, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installation directory information to an authenticated user that could be used in further attacks against the system.

  • CVE-2025-1138MedMay 15, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory listing.

  • CVE-2024-35113MedJan 25, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Control Center 6.2.1 and 6.3.1 could allow an authenticated user to obtain sensitive information exposed through a directory listing.

  • CVE-2021-32511MedJul 7, 2021
    risk 0.28cvss 4.3epss 0.01

    QSAN Storage Manager through directory listing vulnerability in ViewBroserList allows remote authenticated attackers to list arbitrary directories via the file path parameter. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

  • CVE-2021-32510MedJul 7, 2021
    risk 0.28cvss 4.3epss 0.01

    QSAN Storage Manager through directory listing vulnerability in antivirus function allows remote authenticated attackers to list arbitrary directories by injecting file path parameter. The referred vulnerability has been solved with the updated version of QSAN Storage Manager…

  • CVE-2019-5437MedMay 10, 2019
    risk 0.28cvss 5.3epss 0.01

    Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.

  • CVE-2026-41933MedMay 14, 2026
    risk 0.27cvss 5.3epss 0.00

    Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attackers to enumerate files and directories by accessing multiple paths lacking proper index directives in .htaccess files. Attackers can access directories such…

  • CVE-2025-62396MedOct 23, 2025
    risk 0.27cvss 5.3epss 0.00

    An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.

  • CVE-2025-23378LowApr 10, 2025
    risk 0.21cvss 3.3epss 0.00

    Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.

  • CVE-2016-15019MedJan 15, 2023
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was found in tombh jekbox. It has been rated as problematic. This issue affects some unknown processing of the file lib/server.rb. The manipulation leads to exposure of information through directory listing. The attack may be initiated remotely. The patch is…

  • CVE-2014-125069MedJan 8, 2023
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was found in saxman maps-js-icoads. It has been classified as problematic. Affected is an unknown function. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The name of the patch is…

  • CVE-2024-56464LowDec 9, 2025
    risk 0.18cvss 2.7epss 0.00

    IBM QRadar SIEM 7.5 - 7.5.0 UP14 IF01 is affected by an information disclosure vulnerability involving exposure of directory information. IBM has addressed this vulnerability in the latest update.

  • CVE-2024-28766LowJan 27, 2025
    risk 0.16cvss 2.4epss 0.00

    IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the system.

  • CVE-2020-15081MedJul 2, 2020
    risk 0.00cvss 5.3epss 0.02

    In PrestaShop from version 1.5.0.0 and before 1.7.6.6, there is information exposure in the upload directory. The problem is fixed in version 1.7.6.6. A possible workaround is to add an empty index.php file in the upload directory.