Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.
| Software | From | Fixed in |
|---|---|---|
| apache / http_server | 1.3.10 | 1.3.10.x |
| apache / http_server | 1.3.9 | 1.3.9.x |