The AVM KEN! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.Referenceshttp://www.osvdb.org/1282http://www.securityfocus.com/bid/1103http://www.securityfocus.com/templates/archive.pike?list=1&msg=383085010.956159226625.JavaMail.root%40web305-mc.mail.comhttp://archives.neohapsis.com/archives/bugtraq/2000-04/0073.html