NetworkActiv Web Server 3.5.15 allows remote attackers to read script source code via a crafted URL with a "/" (forward slash) after the file extension.
https://exchange.xforce.ibmcloud.com/vulnerabilities/24979
http://www.vupen.com/english/advisories/2006/0783
http://www.securityfocus.com/bid/16895
http://www.securityfocus.com/archive/1/426461/100/0/threaded
http://www.networkactiv.com/WebServer.html