CVE-2003-1138

The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:interchange:2.0.40_21.5:*:i386:*:*:*:*:*

History

20 Nov 2024, 23:46

Type Values Removed Values Added
References () http://www.securityfocus.com/archive/1/342578 - Exploit, Vendor Advisory () http://www.securityfocus.com/archive/1/342578 - Exploit, Vendor Advisory
References () http://www.securityfocus.com/bid/8898 - Vendor Advisory () http://www.securityfocus.com/bid/8898 - Vendor Advisory

Information

Published : 2003-10-27 05:00

Updated : 2024-11-20 23:46


NVD link : CVE-2003-1138

Mitre link : CVE-2003-1138

CVE.ORG link : CVE-2003-1138


JSON object : View

Products Affected

redhat

  • interchange