Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) via a URL with a trailing encoded space (%20).
https://exchange.xforce.ibmcloud.com/vulnerabilities/35038
http://www.securityfocus.com/archive/1/472190/100/0/threaded
http://securityreason.com/securityalert/2832