Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a .. attack in an HTTP GET request.
http://freecode.com/projects/embedthis-goahead-webserver/releases/343539
http://archives.neohapsis.com/archives/bugtraq/2001-02/0022.html