Apache 2.0 before 2.0.44 on Windows platforms allows remote attackers to obtain certain files via an HTTP request that ends in certain illegal characters such as ">", which causes a different filename to be processed and served.
| Software | From | Fixed in |
|---|---|---|
| apache / http_server | 2.0.42 | 2.0.42.x |
| apache / http_server | 2.0.37 | 2.0.37.x |
| apache / http_server | 2.0.39 | 2.0.39.x |
| apache / http_server | 2.0.41 | 2.0.41.x |
| apache / http_server | 2.0.38 | 2.0.38.x |
| apache / http_server | 2.0.40 | 2.0.40.x |
| apache / http_server | 2.0.36 | 2.0.36.x |
| apache / http_server | 2.0.43 | 2.0.43.x |