COMMAND
SlimServe HTTPd
SYSTEMS AFFECTED
SlimServe HTTPd ver. 1.1a
PROBLEM
'se00020' posted following. It is possible to view directory and
(download) files outside of the wwwroot directory. Exploit:
http://127.0.0.1/.../
http://127.0.0.1/.../.../directory/file.xxx
SOLUTION
Disable folder listings (it is enabled by default), which will
secure you from viewing directory outside of the wwwroot
directory. But it is still possible to download or view files
when the location is known.