WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20).
https://exchange.xforce.ibmcloud.com/vulnerabilities/6639
https://euvd.enisa.europa.eu/vulnerability/EUVD-2001-0679