tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2002-2331
http://www.securityfocus.com/bid/6198
http://www.securiteam.com/windowsntfocus/6D00D2061G.html
http://www.kb.cert.org/vuls/id/632633