You're right on the GET requests.. :) ..
Any attacker, pentesters, worth their salt would be able to garner some good info from this.
See reference to vulnerable soft in the post published.
Cheers.