Description
File and directory paths reveal information about the structure of the file system of the underlying OS. While this information does not directly impact the target, it provides valuable insights attackers can exploit. Attackers can leverage disclosed paths to gain knowledge of the system’s configuration and potentially identify additional attack vectors.
Recommendation
If the disclosure is unintentional, address the underlying reason causing it and ensure that paths are not revealed due to errors or misconfigurations. Implement robust access controls and input validation to prevent unintended disclosure of sensitive information.
References
Could your website be exposed too?
SmartScanner can check your website for Unix Path Disclosure and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Windows Path Disclosure - Vulnerability
- Path Disclosure in Robots.txt - Vulnerability
- PHP Version Disclosure - Vulnerability
- Unreferenced Source Code Disclosure - Vulnerability


