CVE-2001-0925 describes a directory listing vulnerability in Apache HTTP Server versions prior to 1.3.19. A remote attacker can exploit this flaw by sending a specially crafted HTTP request with numerous slash characters, causing mod_negotiation, mod_dir, or mod_autoindex to mishandle the path and display directory contents instead of the intended index.html file. This vulnerability has a CVSS score of 5.0 (Medium), indicating low attack complexity and no authentication required, leading to a potential information disclosure impact. While not listed in CISA's KEV catalog and lacking Metasploit or Nuclei modules, multiple ExploitDB entries confirm the existence of public exploit code, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.11CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.11:*:*:*:*:*:*:* | ||
1.3.12CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.12:*:*:*:*:*:*:* | ||
1.3.14CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.14:*:*:*:*:*:*:* | ||
1.3.17CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.17:*:*:*:*:*:*:* | ||
2.2CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:2.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.