First published: Mon Mar 12 2001(Updated: )
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache HTTP Server | =1.3.11 | |
Apache HTTP Server | =1.3.12 | |
Apache HTTP Server | =1.3.14 | |
Apache HTTP Server | =1.3.17 | |
Debian GNU/Linux | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0925 has a medium severity rating as it allows directory listing, which can expose sensitive information.
To fix CVE-2001-0925, upgrade the Apache HTTP Server to version 1.3.19 or later.
CVE-2001-0925 affects Apache HTTP Server versions 1.3.11 through 1.3.17.
Yes, CVE-2001-0925 can be exploited remotely by attackers to list directories.
CVE-2001-0925 involves the mod_negotiation, mod_dir, and mod_autoindex modules of Apache.