The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a crafted URI, as demonstrated by an encoded forward slash.
http://www.securityfocus.com/bid/60569
http://www.openwall.com/lists/oss-security/2013/06/14/11