First published: Mon Oct 27 2003(Updated: )
The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Interchange | =2.0.40_21.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.