Security Advisory

CVE-2001-0925

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2002-02-02 05:00:00
Last updated 2024-08-08 04:37:07
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.