CVE-2003-1138

The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).
References
Link Resource
http://www.securityfocus.com/archive/1/342578 Exploit Vendor Advisory
http://www.securityfocus.com/bid/8898 Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:interchange:2.0.40_21.5:*:i386:*:*:*:*:*

Information

Published : 2003-10-26 21:00

Updated : 2008-09-05 13:36


NVD link : CVE-2003-1138

Mitre link : CVE-2003-1138


JSON object : View

Advertisement

dedicated server usa

Products Affected

redhat

  • interchange