Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to bypass protection mechanisms and read the source of files via multiple '/' (slash) characters in the URI.
http://www.vupen.com/english/advisories/2008/0079
http://www.securityfocus.com/bid/27117
http://www.kb.cert.org/vuls/id/553235
http://www.igniterealtime.org/community/message/163752
http://secunia.com/advisories/28547
http://secunia.com/advisories/28322