The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL with a %00 (null) character after the file extension.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-0454
http://security.gentoo.org/glsa/glsa-200502-21.xml