Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Informations
Name CVE-2001-0925 First vendor Publication 2001-03-12
Vendor Cve Last vendor Modification 2023-11-07

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Cvss Base Score 5 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0925

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE/SANS Top 25)

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 4
Os 1

OpenVAS Exploits

Date Description
2008-01-17 Name : Debian Security Advisory DSA 067-1 (apache,apache-ssl)
File : nvt/deb_067_1.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
9700 Apache HTTP Server mod_autoindex Multiple Slash Request Forced Directory Listing

Apache HTTP server contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker sends a specially crafted request, consisting of a large amount of slash characters '/', to a default apache install. The default enabled mod_autoindex module will disclose a directory listing of the root directory instead of the index.html, resulting in a loss of confidentiality.
9699 Apache HTTP Server mod_dir Multiple Slash Request Forced Directory Listing

Apache HTTP server contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker sends a specially crafted request, consisting of a large amount of slash characters '/', to a default apache install. The default enabled mod_dir module will disclose a directory listing of the root directory instead of the index.html, resulting in a loss of confidentiality.
9698 Apache HTTP Server mod_negotiation Multiple Slash Request Forced Directory Li...

Apache HTTP server contains a flaw that may lead to an unauthorized information disclosure.  The issue is triggered when a remote attacker sends a specially crafted request, consisting of a large amount of slash characters '/', to a default apache install. The default enabled mod_negotiation, mod_dir/mod_autoindex modules will disclose a directory listing of the root directory instead of the index.html, resulting in a loss of confidentiality.

Snort® IPS/IDS

Date Description
2014-01-10 apache directory disclosure attempt
RuleID : 1156-community - Revision : 17 - Type : SERVER-WEBAPP
2014-01-10 apache directory disclosure attempt
RuleID : 1156 - Revision : 17 - Type : SERVER-WEBAPP

Nessus® Vulnerability Scanner

Date Description
2004-09-29 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-067.nasl - Type : ACT_GATHER_INFO
2004-07-31 Name : The remote Mandrake Linux host is missing one or more security updates.
File : mandrake_MDKSA-2001-077.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab3...
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f...
https://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f6988585512...
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f...
Source Url
BID http://www.securityfocus.com/bid/2503
BUGTRAQ http://www.securityfocus.com/archive/1/168497
http://www.securityfocus.com/archive/1/178066
http://www.securityfocus.com/archive/1/193081
http://www.securityfocus.com/cgi-bin/archive.pl?id=1&start=2002-01-27&...
CONFIRM http://www.apacheweek.com/features/security-13
DEBIAN http://www.debian.org/security/2001/dsa-067
ENGARDE http://www.linuxsecurity.com/advisories/other_advisory-1452.html
MANDRAKE http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-077.php3
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/6921

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
Date Informations
2023-11-07 21:48:12
  • Multiple Updates
2021-07-06 21:23:28
  • Multiple Updates
2021-06-06 17:23:05
  • Multiple Updates
2021-05-04 12:01:50
  • Multiple Updates
2021-04-22 01:01:58
  • Multiple Updates
2021-03-30 17:22:45
  • Multiple Updates
2020-05-23 01:35:37
  • Multiple Updates
2020-05-23 00:14:44
  • Multiple Updates
2017-12-19 09:22:06
  • Multiple Updates
2016-10-13 01:00:35
  • Multiple Updates
2016-04-26 11:57:50
  • Multiple Updates
2014-02-17 10:24:03
  • Multiple Updates
2014-01-19 21:21:31
  • Multiple Updates
2013-05-11 12:05:47
  • Multiple Updates