Description
Due to incorrect configuration, the web application discloses a full path to a file with source code, which generated a response, in the "X-SourceFiles" header.
Remediation
Hide X-SourceFiles header
References
Related Vulnerabilities
Test CGI script leaking environment variables
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6627)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-5835)
[Possible] Password Transmitted over Query String
SharePoint Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-8580)