Directory traversal vulnerability in Macromedia JRun Web Server (JWS) 2.3.3, 3.0 and 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP GET request.
http://www.securityfocus.com/bid/3666
http://www.macromedia.com/v1/handlers/index.cfm?ID=22290&Method=Full