Compliance Node Overview
MITRE CAPEC-127 (Directory Indexing) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary crafts a request to a target that results in the target listing/indexing the content of a directory as output. One common method of triggering directory contents as output is to construct a request containing a path that terminates in a directory name rather than a file name since many applications are configured to provide a list of the directory's contents when such a request is received. Likelihood of attack: High. Typical severity: Medium. Maps to weaknesses CWE-424, CWE-425, CWE-288, CWE-285, and others. Relates to MITRE ATT&CK T1083.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/127.html
SHA-256 integrity: e1856801b17ed33b8165996d40c5cdb35630c17f0c0c2ec9d07a304da131db86
Primary Citations — 11 traced to source
- MITRE CAPEC-127: Directory Indexing (https://capec.mitre.org/data/definitions/127.html)
- CWE-424: underlying weakness (http://cwe.mitre.org/data/definitions/424.html)
+ 9 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.