A directory was discovered that contains an object referenced in a post request or query string, and which has a name thatcould easily be guessed by an attacker. The primary danger from an attacker discovering this directory would arise from theinformation he could gather from its contents, such as what language was used to code the web application.Recommendations include restricting access to important directories or files by adopting a "need to know" requirement forboth the document and server root, and turning off features such as Automatic Directory Listings that provide information thatcould be utilized by an attacker when formulating or conducting an attack.