I don't know, but I think "putting up a web server" qualifies for "positive effort" ;-) And while it does take extra work to ensure an Intranet isn't available on the public web, or that it's correctly configured to require a login to view documents ... there has to be a line somewhere.
I mean, I've stumbled on FTP sites that allow anonymous users. By providing no password and still seeing content, would I have "hacked" them? It's a configuration issue, and password prompts are just that. Of course, where do you then draw the line? If you call it a security flaw that the documents were public, then accessing them could be an exploit. But... a very flimsy one, since we rarely execute injection attacks to visit websites, but we often click links on Google. The bar is clearly very low. ;-)
This might, of course, change if the access was not indicated on Google but instead on a site like shodanhq.com ...