<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CWE-541 on ZAP</title>
    <link>/alerttags/cwe-541/</link>
    <description>Recent content in CWE-541 on ZAP</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="/alerttags/cwe-541/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Properties File Disclosure - /WEB-INF folder</title>
      <link>/docs/alerts/10045-2/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10045-2/</guid>
      <description>&lt;p&gt;A Java class in the /WEB-INF folder disclosed the presence of the properties file. Properties file are not intended to be publicly accessible, and typically contain configuration information, application credentials, or cryptographic keys.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Source Code Disclosure - /WEB-INF Folder</title>
      <link>/docs/alerts/10045-1/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/10045-1/</guid>
      <description>&lt;p&gt;Java source code was disclosed by the web server in Java class files in the WEB-INF folder. The class files can be dis-assembled to produce source code which very closely matches the original source code.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Source Code Disclosure - File Inclusion</title>
      <link>/docs/alerts/43/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/43/</guid>
      <description>&lt;p&gt;The Path Traversal attack technique allows an attacker access to files, directories, and commands that potentially reside outside the web document root directory. An attacker may manipulate a URL in such a way that the web site will execute or reveal the contents of arbitrary files anywhere on the web server. Any device that exposes an HTTP-based interface is potentially vulnerable to Path Traversal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Source Code Disclosure - Git</title>
      <link>/docs/alerts/41/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/41/</guid>
      <description>&lt;p&gt;The source code for the current page was disclosed by the web server.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Source Code Disclosure - SVN</title>
      <link>/docs/alerts/42/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/docs/alerts/42/</guid>
      <description>&lt;p&gt;The source code for the current page was disclosed by the web server.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
