• CVSS Severity Rating • Fix Information • Vulnerable Software Versions • SCAP Mappings • CPE Information
Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.
Note: References are provided for the convenience of the reader to help distinguish between vulnerabilities. The list is not intended to be complete.
Assigning CNA
MITRE Corporation
Date Record Created
20011008 Disclaimer: The record creation date may reflect when the CVE ID was allocated or reserved, and does not necessarily indicate when this vulnerability was discovered, shared with the affected vendor, publicly disclosed, or updated in CVE.
Phase (Legacy)
Modified (20071115)
Votes (Legacy)
ACCEPT(5) Armstrong, Baker, Cole, Foat, Wall
MODIFY(1) Frech
NOOP(1) Christey
Comments (Legacy)
 Christey> The initial description originally stated that this was a
   denial of service, but it's really a directory listing
   problem.  I changed the description accordingly.
 Frech> XF:apache-slash-directory-listing(6921)
 Christey> XF:apache-slash-directory-listing(6921) is identifying a
   different issue that has not had a CAN assigned yet.
 Christey> SGI:20020301-01-P
 Christey> CVE-2001-0925 and CVE-2001-0729 are different issues.
   CVE-2001-0925 only applies to versions before 1.3.19, whereas
   CVE-2001-0729 applies to 1.3.20, and only Windows.
   The Change Log at
   specifically mentions these CANs separately.

Proposed (Legacy)
This is an record on the CVE List, which provides common identifiers for publicly known cybersecurity vulnerabilities.