CVE-2001-1013
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/09/2001
Last modified:
03/04/2025
Description
Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:redhat:linux:7.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0083.html
- http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0087.html
- http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0094.html
- http://www.securityfocus.com/archive/1/213667
- http://www.securityfocus.com/bid/3335
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7129
- http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0083.html
- http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0087.html
- http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0094.html
- http://www.securityfocus.com/archive/1/213667
- http://www.securityfocus.com/bid/3335
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7129