CVE-2003-1138
MEDIUM 5.0EPSS 5.4%
The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).
- CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 5.44% chance of exploitation in the next 30 days, 92th percentile
- Published
- 2005-05-10
- Updated
- 2024-09-16