Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.
http://www.securityfocus.com/bid/22083
http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html
http://www.apacheweek.com/issues/01-09-28#security