CVE-2001-0925
published 2001-03-12CVE-2001-0925: The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a…
PriorityP428medium5CVSS 2.0
AVNACLAuNCPINAN
EXPLOIT
EPSS
75.24%
99.5th percentile
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| debian | debian_linux | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP GET requests with an abnormally long URI consisting entirely of repeated '/' slash characters (thousands of slashes), which is the attack vector for this CVE. ↗
- →Alert on HTTP responses containing 'Index of' in the body from Apache servers, which indicates successful directory listing disclosure triggered by the exploit. ↗
- →Approximately 4060 or more slash characters in the URI path are needed to trigger the stat() overflow condition on Debian; monitor for GET requests with URI length exceeding 4000 characters composed of '/' characters. ↗
- →The vulnerability requires mod_dir, mod_autoindex, and mod_negotiation to be enabled along with 'Indexes' and 'MultiView' Options; audit Apache configs for these combinations on versions prior to 1.3.19. ↗
- →The exploit iterates slash counts from a low to high range (default 1–8192) probing for a 200 HTTP response with 'index of' in the body; detect iterative GET requests with incrementally growing all-slash URIs from a single source IP. ↗
- ·The vulnerability only triggers when mod_dir, mod_autoindex, AND mod_negotiation are all enabled simultaneously, AND the target directory has both 'Indexes' and 'MultiView' Options set — disabling any of these prevents exploitation. ↗
- ·Apache 1.3.19 and later are not vulnerable; the exploit was confirmed not to work against Apache 1.3.20 (e.g., SuSE 7.3 default install). ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Apache 1.3 - Artificially Long Slash Path Directory Listing (2)
exploitdb·2002-02-21
CVE-2001-0925 Apache 1.3 - Artificially Long Slash Path Directory Listing (2)
Apache 1.3 - Artificially Long Slash Path Directory Listing (2)
---
// source: https://www.securityfocus.com/bid/2503/info
Apache HTTPD is the Apache Web Server, freely distributed and actively maintained by the Apache Software Foundation. It is a freely available and widely used software package, included with various implementations of the UNIX operating system and can be used on Microsoft Windows operating systems.
A problem in the package could allow directory indexing and path discovery. In a default configuration, Apache enables mod_dir, mod_autoindex, and mod_negotiation. However, by sending the Apache server a custom-crafted request consisting of a long path name created artificially by using numerous slashes, an attacker can cause these modules to misbehave, allowing the attac
Exploit-DB
Apache 1.3 - Artificially Long Slash Path Directory Listing (4)
exploitdb·2001-06-13
CVE-2001-0925 Apache 1.3 - Artificially Long Slash Path Directory Listing (4)
Apache 1.3 - Artificially Long Slash Path Directory Listing (4)
---
source: https://www.securityfocus.com/bid/2503/info
Apache HTTPD is the Apache Web Server, freely distributed and actively maintained by the Apache Software Foundation. It is a freely available and widely used software package, included with various implementations of the UNIX operating system and can be used on Microsoft Windows operating systems.
A problem in the package could allow directory indexing and path discovery. In a default configuration, Apache enables mod_dir, mod_autoindex, and mod_negotiation. However, by sending the Apache server a custom-crafted request consisting of a long path name created artificially by using numerous slashes, an attacker can cause these modules to misbehave, allowing the attacker
Exploit-DB
Apache 1.3 - Artificially Long Slash Path Directory Listing (3)
exploitdb·2001-06-13
CVE-2001-0925 Apache 1.3 - Artificially Long Slash Path Directory Listing (3)
Apache 1.3 - Artificially Long Slash Path Directory Listing (3)
---
source: https://www.securityfocus.com/bid/2503/info
Apache HTTPD is the Apache Web Server, freely distributed and actively maintained by the Apache Software Foundation. It is a freely available and widely used software package, included with various implementations of the UNIX operating system and can be used on Microsoft Windows operating systems.
A problem in the package could allow directory indexing and path discovery. In a default configuration, Apache enables mod_dir, mod_autoindex, and mod_negotiation. However, by sending the Apache server a custom-crafted request consisting of a long path name created artificially by using numerous slashes, an attacker can cause these modules to misbehave, allowing the attacker
Exploit-DB
Apache 1.3 - Artificially Long Slash Path Directory Listing (1)
exploitdb·2001-06-13
CVE-2001-0925 Apache 1.3 - Artificially Long Slash Path Directory Listing (1)
Apache 1.3 - Artificially Long Slash Path Directory Listing (1)
---
source: https://www.securityfocus.com/bid/2503/info
Apache HTTPD is the Apache Web Server, freely distributed and actively maintained by the Apache Software Foundation. It is a freely available and widely used software package, included with various implementations of the UNIX operating system and can be used on Microsoft Windows operating systems.
A problem in the package could allow directory indexing and path discovery. In a default configuration, Apache enables mod_dir, mod_autoindex, and mod_negotiation. However, by sending the Apache server a custom-crafted request consisting of a long path name created artificially by using numerous slashes, an attacker can cause these modules to misbehave, allowing the attacker
No writeups or analysis indexed.
http://www.apacheweek.com/features/security-13http://www.debian.org/security/2001/dsa-067http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-077.php3http://www.linuxsecurity.com/advisories/other_advisory-1452.htmlhttp://www.securityfocus.com/archive/1/168497http://www.securityfocus.com/archive/1/178066http://www.securityfocus.com/archive/1/193081http://www.securityfocus.com/bid/2503http://www.securityfocus.com/cgi-bin/archive.pl?id=1&start=2002-01-27&end=2002-02-02&mid=199857&threads=1https://exchange.xforce.ibmcloud.com/vulnerabilities/6921https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttp://www.apacheweek.com/features/security-13http://www.debian.org/security/2001/dsa-067http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-077.php3http://www.linuxsecurity.com/advisories/other_advisory-1452.htmlhttp://www.securityfocus.com/archive/1/168497http://www.securityfocus.com/archive/1/178066http://www.securityfocus.com/archive/1/193081http://www.securityfocus.com/bid/2503http://www.securityfocus.com/cgi-bin/archive.pl?id=1&start=2002-01-27&end=2002-02-02&mid=199857&threads=1https://exchange.xforce.ibmcloud.com/vulnerabilities/6921https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
2001-03-12
Published