ASP.NET 2.0 includes site navigation features including sitemaps, automatic
generation of "breadcrumb" links on pages, etc. An ASP.NET 2.0 application can
include a file named web.sitemap within the application root. This file is meant
to be used on the back-end to drive the site navigation features and should
never be accessible remotely.
The web.sitemap file contains a list of links on the server that can
be used by malicious users to gather information about hidden pages within
the web application.