# CVE-2003-1138

## Summary

- **CVE ID:** CVE-2003-1138
- **Severity:** UNKNOWN
- **CVSS Score:** 0.21
- **CWE:** N/A
- **Published:** May 10, 2005
- **Last Modified:** Mar 16, 2026

## Description

The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](http://www.securityfocus.com/bid/8898)
- [CNA](http://www.securityfocus.com/archive/1/342578)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 5.23%
- **EPSS Percentile:** 89.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._