The ShellExample.cgi script in 4D WebSTAR 5.3.2 and earlier allows remote attackers to list arbitrary directories via a URL with the desired path and a "*" (asterisk) character.
https://exchange.xforce.ibmcloud.com/vulnerabilities/16687
http://www.securityfocus.com/bid/10721
http://www.atstake.com/research/advisories/2004/a071304-1.txt