GoAhead webserver 2.1 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.
https://exchange.xforce.ibmcloud.com/vulnerabilities/6400
http://freecode.com/projects/embedthis-goahead-webserver/releases/343539
http://archives.neohapsis.com/archives/bugtraq/2001-04/0281.html