Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:10704
Category:Web Servers
Title:Apache HTTP Server Directory Listing
Summary:By making a request to the Apache HTTP server ending in '?M=A' it is sometimes possible to obtain a; directory listing even if an index.html file is present.;; It appears that it is possible to retrieve a directory listing from the root of the Apache; HTTP server being tested. However, this could be because there is no 'index.html' or similar; default file present.
Description:Summary:
By making a request to the Apache HTTP server ending in '?M=A' it is sometimes possible to obtain a
directory listing even if an index.html file is present.

It appears that it is possible to retrieve a directory listing from the root of the Apache
HTTP server being tested. However, this could be because there is no 'index.html' or similar
default file present.

Solution:
Unless it is required, turn off Indexing by making the appropriate changes to your
httpd.conf file.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: BugTraq ID: 3009
Common Vulnerability Exposure (CVE) ID: CVE-2001-0731
http://www.securityfocus.com/bid/3009
Bugtraq: 20010709 How Google indexed a file with no external link (Google Search)
http://www.securityfocus.com/archive/1/20010709214744.A28765@brasscannon.net
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2001:077
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9@%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5@%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920@%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4@%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e@%3Ccvs.httpd.apache.org%3E
http://www.redhat.com/support/errata/RHSA-2001-126.html
http://www.redhat.com/support/errata/RHSA-2001-164.html
SGI Security Advisory: 20020301-01-P
ftp://patches.sgi.com/support/free/security/advisories/20020301-01-P
XForce ISS Database: apache-multiviews-directory-listing(8275)
https://exchange.xforce.ibmcloud.com/vulnerabilities/8275
CopyrightCopyright (C) 2001 Matt Moore

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.