First published: Wed May 31 2000(Updated: )
The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Http Server | =1.3.6 | |
Apache Http Server | =1.3.9 | |
Apache Http Server | =1.3.11 | |
Apache Http Server | =1.3.12 | |
IBM HTTP Server | =1.3.3 | |
IBM HTTP Server | =1.3.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0505 is classified as a medium severity vulnerability.
To fix CVE-2000-0505, you should upgrade to a patched version of Apache HTTP Server or configure security settings to disable directory listing.
CVE-2000-0505 affects Apache HTTP Server versions 1.3.3 to 1.3.12 and IBM HTTP Server versions 1.3.3 and 1.3.6.2.
CVE-2000-0505 allows remote attackers to list directory contents, exposing sensitive information.
CVE-2000-0505 is applicable to the Windows platforms running the specified versions of Apache and IBM HTTP Server.