Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to obtain the source code for scripts by appending encoded space (%20) or . (%2e) characters to an HTTP request for the script, e.g. view_broadcast.cgi.
AV:N/AC:L/Au:N/C:P/I:N/A:N
This vulnerability has a 1.42% probability of being exploited in the next 30 days, ranking higher than 72% of all scored CVEs.