CVE-2001-0925
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1)…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 75.2%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 75.24% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- apache/http server · debian/debian linux
- Source
- cve@mitre.org
References
- http://www.apacheweek.com/features/security-13Vendor Advisory
- http://www.debian.org/security/2001/dsa-067Third Party Advisory
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-077.php3Broken Link
- http://www.linuxsecurity.com/advisories/other_advisory-1452.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/168497Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/178066Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/193081Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/2503Exploit, Patch, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/cgi-bin/archive.pl?id=1&start=2002-01-27&end=2002-02-02&mid=199857&threads=1Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6921Third Party Advisory, VDB Entry
- https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
- http://www.apacheweek.com/features/security-13Vendor Advisory
- http://www.debian.org/security/2001/dsa-067Third Party Advisory
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-077.php3Broken Link
- http://www.linuxsecurity.com/advisories/other_advisory-1452.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/168497Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/178066Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/193081Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/2503Exploit, Patch, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/cgi-bin/archive.pl?id=1&start=2002-01-27&end=2002-02-02&mid=199857&threads=1Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6921Third Party Advisory, VDB Entry
- https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.