Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2) list directory contents via a trailing null character.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.139
EPSS Ranking 94.0%