VYPR

CWE-548

Exposure of Information Through Directory Listing

VariantDraft

Description

The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (57)

page 3 of 3
  • CVE-2025-45320MedMay 5, 2025
    risk 0.34cvss 5.3epss 0.00

    A Directory Listing Vulnerability was found in the /osms/Requester/ directory of the Kashipara Online Service Management Portal V1.0.

  • CVE-2024-3707MedApr 12, 2024
    risk 0.34cvss 5.3epss 0.00

    Information exposure vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to enumerate all files in the web tree by accessing a php file.

  • CVE-2021-45446MedNov 2, 2022
    risk 0.33cvss 5.0epss 0.00

    A vulnerability in Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not cascade the hidden property to the children of the Home folder.  This directory listing provides an attacker with the complete index of all the resources…

  • CVE-2025-2827MedJul 8, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6, and 6.2.0.0 through 6.2.0.4 could disclose sensitive installation directory information to an authenticated user that could be used in further attacks against the system.

  • CVE-2025-1138MedMay 15, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory listing.

  • CVE-2024-35113MedJan 25, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM Control Center 6.2.1 and 6.3.1 could allow an authenticated user to obtain sensitive information exposed through a directory listing.

  • CVE-2021-32511MedJul 7, 2021
    risk 0.28cvss 4.3epss 0.01

    QSAN Storage Manager through directory listing vulnerability in ViewBroserList allows remote authenticated attackers to list arbitrary directories via the file path parameter. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

  • CVE-2021-32510MedJul 7, 2021
    risk 0.28cvss 4.3epss 0.01

    QSAN Storage Manager through directory listing vulnerability in antivirus function allows remote authenticated attackers to list arbitrary directories by injecting file path parameter. The referred vulnerability has been solved with the updated version of QSAN Storage Manager…

  • CVE-2019-5437MedMay 10, 2019
    risk 0.28cvss 5.3epss 0.01

    Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according to the harp server rules.Vulnerable versions are <= 0.29.0 and no fix was applied to our knowledge.

  • CVE-2026-41933MedMay 14, 2026
    risk 0.27cvss 5.3epss 0.00

    Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attackers to enumerate files and directories by accessing multiple paths lacking proper index directives in .htaccess files. Attackers can access directories such…

  • CVE-2025-62396MedOct 23, 2025
    risk 0.27cvss 5.3epss 0.00

    An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.

  • CVE-2025-23378LowApr 10, 2025
    risk 0.21cvss 3.3epss 0.00

    Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.

  • CVE-2016-15019MedJan 15, 2023
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was found in tombh jekbox. It has been rated as problematic. This issue affects some unknown processing of the file lib/server.rb. The manipulation leads to exposure of information through directory listing. The attack may be initiated remotely. The patch is…

  • CVE-2014-125069MedJan 8, 2023
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was found in saxman maps-js-icoads. It has been classified as problematic. Affected is an unknown function. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The name of the patch is…

  • CVE-2024-56464LowDec 9, 2025
    risk 0.18cvss 2.7epss 0.00

    IBM QRadar SIEM 7.5 - 7.5.0 UP14 IF01 is affected by an information disclosure vulnerability involving exposure of directory information. IBM has addressed this vulnerability in the latest update.

  • CVE-2024-28766LowJan 27, 2025
    risk 0.16cvss 2.4epss 0.00

    IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the system.

  • CVE-2020-15081MedJul 2, 2020
    risk 0.00cvss 5.3epss 0.02

    In PrestaShop from version 1.5.0.0 and before 1.7.6.6, there is information exposure in the upload directory. The problem is fixed in version 1.7.6.6. A possible workaround is to add an empty index.php file in the upload directory.