Directory traversal vulnerability in Visual Synapse HTTP Server 1.0 RC1 through RC3, and 0.60 and earlier, allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
http://www.syhunt.com/advisories/?id=vs-httpd-dirtrav
http://www.securityfocus.com/archive/1/514167/100/0/threaded