CVE-2001-1013

Apache - Info Disclosure

Title source: llm

Description

Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Gabriel A Maggiotti · phpremotelinux
https://www.exploit-db.com/exploits/21112
metasploit SCANNER
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/apache_userdir_enum.rb

Scores

EPSS 0.6812
EPSS Percentile 98.6%

Details

Status published
Products (1)
redhat/linux 7.0
Published Sep 12, 2001
Tracked Since Feb 18, 2026