Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to read arbitrary files via a "\/" in a pathname argument, as demonstrated by "download \/server.cfg".
https://exchange.xforce.ibmcloud.com/vulnerabilities/17892
http://www.securityfocus.com/bid/11551
http://web.archive.org/web/20041130092749/www.r1ch.net/stuff/r1q2/