The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.
| Software | From | Fixed in |
|---|---|---|
| apache / http_server | 1.3.9 | 1.3.9.x |
| apache / http_server | 1.3.11 | 1.3.11.x |
| ibm / http_server | 1.3.3 | 1.3.3.x |
| ibm / http_server | 1.3.6.2 | 1.3.6.2.x |
| apache / http_server | 1.3.6 | 1.3.6.x |
| apache / http_server | 1.3.12 | 1.3.12.x |