parse_xml.cgi in Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to obtain the source code for parseable files via the filename parameter.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2003-0417
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0040.html