> For the complete documentation index, see [llms.txt](https://pnpt.adot8.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://pnpt.adot8.com/external-pentest-playbook/common-pentest-findings/information-disclosure.md).

# Information Disclosure

## Overview

Information disclosure will come in many different types and rank from **Critical-Low.** A lot of them won't lead to direct exploits but they're definitely things adversaries can put in their back pocket to use later&#x20;

## Example 1

<figure><img src="/files/eFwKWFicCa3Kyjf8nWls" alt=""><figcaption><p>Information disclosure via Calender form. Username enumeration was possible through the error</p></figcaption></figure>

<figure><img src="/files/azLdfyJCD57O0TYPEZ9C" alt=""><figcaption><p>Evidence and Remediation</p></figcaption></figure>

## Example 2

{% hint style="info" %}
More for when you're running low on findings and have time to check. Information is information
{% endhint %}

<figure><img src="/files/6fAewf0pdY5vDmLYBfxY" alt=""><figcaption><p>Information disclosure via web server</p></figcaption></figure>

<figure><img src="/files/TXtO7vTTfLLDJWcZ5N8x" alt=""><figcaption><p>Evidence and Remediation</p></figcaption></figure>
