QID 150356
Date Published: 2021-08-26
QID 150356: Sensitive Files Disclosure
A potentially sensitive file was discovered on the Web server. This file may or may not be directly associated with the web application.
Files Checked:
nginx.conf, .htpasswd, key.pem, certificate.pem
QID Detection Logic:
This QID sends a GET request to the target server to retrieve the file content.
Contents of this file may disclose sensitive information which could give technical edge to an attacker to learn more about his target.
Solution
Verify that access to this file is permitted. If necessary, remove it or apply access controls to it.
Vendor References
CVEs related to QID 150356
Software Advisories
| Advisory ID | Software | Component | Link |
|---|