Yes. Apache misconfigurations were a big one iirc. There were also basic auth files, databases and probably classified/proprietary information.
Similar to how the telephone network used to have all kinds of unsecured entry points that people explored, leading to business phone systems, strange modems, and even international “trunk” lines and operator capabilities.
It was always surprising how many servers accidentally exposed sensitive files.