Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to bypass protection mechanisms and read the source of files via multiple ‘/’ (slash) characters in the URI.
jira.codehaus.org/browse/JETTY-386
jira.codehaus.org/browse/JETTY/fixforversion/13950
osvdb.org/39855
secunia.com/advisories/28322
secunia.com/advisories/28547
www.igniterealtime.org/community/message/163752
www.kb.cert.org/vuls/id/553235
www.securityfocus.com/bid/27117
www.vupen.com/english/advisories/2008/0079