PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing %5c (encoded backslash) sequences.
Affected Software
| Name | Vendor | Start Version | End Version | 
| Http_server | Apache | 1.3 (including) | 1.3 (including) | 
References