Description
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.
Affected products
- Apple / darwin_streaming_server4.1.2 – 4.1.2
- Apple / quicktime_streaming_server4.1.1 – 4.1.1