CVE-2003-1138

The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).
References
Link Resource
http://www.securityfocus.com/archive/1/342578 Exploit Vendor Advisory
http://www.securityfocus.com/bid/8898 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:interchange:2.0.40_21.5:*:i386:*:*:*:*:*

History

No history.

Information

Published : 2003-10-27 05:00

Updated : 2024-02-28 10:24


NVD link : CVE-2003-1138

Mitre link : CVE-2003-1138

CVE.ORG link : CVE-2003-1138


JSON object : View

Products Affected

redhat

  • interchange