The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).
Link | Tags |
---|---|
http://www.securityfocus.com/bid/8898 | vdb entry vendor advisory |
http://www.securityfocus.com/archive/1/342578 | mailing list exploit vendor advisory |