VulnerabilityModified
CVE-2001-1449
The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
HIGH 7.5EPSS 7.80%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.80%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 7.80% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- apache/http server · mandrakesoft/mandrake single network firewall · mandrakesoft/mandrake linux · mandrakesoft/mandrake linux corporate server
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/913704Patch, US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2001:077-2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8029
- http://www.kb.cert.org/vuls/id/913704Patch, US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2001:077-2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8029
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.