CVE-2003-1138
Last modified
CVE-2003-1138 is a vulnerability of currently unknown severity. The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).. EPSS estimates a 5.44% chance of exploitation in the next 30 days.
Description
The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Interchange | 2.0.40_21.5 |
References
- http://www.securityfocus.com/archive/1/342578Exploit, Vendor Advisory
- http://www.securityfocus.com/bid/8898Vendor Advisory
- http://www.securityfocus.com/archive/1/342578Exploit, Vendor Advisory
- http://www.securityfocus.com/bid/8898Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-1138?
How severe is CVE-2003-1138?
How do I fix CVE-2003-1138?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2003
- CVE-2003-1132The DNS server for Cisco Content Service Switch (CSS) 11000 …
- CVE-2003-1133Rit Research Labs The Bat! 1.0.11 through 2.0 creates new ac…
- CVE-2003-1134Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause…
- CVE-2003-1135Buffer overflow in Yahoo! Messenger 5.6 allows remote attack…
- CVE-2003-1136Cross-site scripting (XSS) vulnerability in Chi Kien Uong Gu…
- CVE-2003-1137Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote atta…
- CVE-2003-1139Musicqueue 1.2.0 allows local users to overwrite arbitrary f…
- CVE-2003-1140Buffer overflow in Musicqueue 1.2.0 allows local users to ex…
- CVE-2003-1141Buffer overflow in NIPrint 4.10 allows remote attackers to e…
- CVE-2003-1142Help in NIPrint LPD-LPR Print Server 4.10 and earlier execut…
- CVE-2003-1143Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First…
- CVE-2003-1144Buffer overflow in the log viewing interface in Perception L…
Are you affected by CVE-2003-1138?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
