The HTTP proxy service in Server Admin for Mac OS X 10.3.9 does not restrict access when it is enabled, which allows remote attackers to use the proxy.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-1343
http://lists.apple.com/archives/security-announce/2005/May/msg00001.html