Description
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.
Affected products
- apache / http_server1.3.12 β 1.3.12
- SUSE / suse_linux6.0 β 6.0
- SUSE / suse_linux6.1 β 6.1
- SUSE / suse_linux6.1 β 6.1
- SUSE / suse_linux6.2 β 6.2
- SUSE / suse_linux6.3 β 6.3
- SUSE / suse_linux6.3 β 6.3
- SUSE / suse_linux6.3 β 6.3
- SUSE / suse_linux6.4 β 6.4
- SUSE / suse_linux6.4 β 6.4
- SUSE / suse_linux6.4 β 6.4
- SUSE / suse_linux7.0 β 7.0