Bajie HTTP web server 0.30a allows remote attackers to read arbitrary files via a URL that contains a "....", a variant of the dot dot directory traversal attack.Referenceshttp://archives.neohapsis.com/archives/bugtraq/2000-07/0426.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/5021http://www.securityfocus.com/bid/1522