The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
2001-11-28T05:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | http_server | 1.3 | Yes |
Application | apache | http_server | 1.3.1 | Yes |
Application | apache | http_server | 1.3.3 | Yes |
Application | apache | http_server | 1.3.4 | Yes |
Application | apache | http_server | 1.3.6 | Yes |
Application | apache | http_server | 1.3.9 | Yes |
Application | apache | http_server | 1.3.11 | Yes |
Application | apache | http_server | 1.3.12 | Yes |
Application | apache | http_server | 1.3.14 | Yes |
Application | apache | http_server | 1.3.17 | Yes |
Application | apache | http_server | 1.3.18 | Yes |
Application | mandrakesoft | mandrake_single_network_firewall | 7.2 | Yes |
Operating System | mandrakesoft | mandrake_linux | 7.1 | Yes |
Operating System | mandrakesoft | mandrake_linux | 7.3 | Yes |
Operating System | mandrakesoft | mandrake_linux | 8.0 | Yes |
Operating System | mandrakesoft | mandrake_linux_corporate_server | 1.0.1 | Yes |