The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.
No PoCs from references.
- https://github.com/LyticOnaope/ZHVA