Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.
| Software | From | Fixed in |
|---|---|---|
| apache / http_server | 1.3.12 | 1.3.12.x |
| apache / http_server | 1.3.9 | 1.3.9.x |
| apache / http_server | 1.3.11 | 1.3.11.x |