A vulnerability in tHTTPd allows remote attackers to traverse into directories that are outside the bounding HTML root directory (when chroot is not enforced).
Credit:
The information has been provided by Marcus Breiing.
Vulnerable systems:
* tHTTPd version 2.21 up to version 2.23b1
Immune systems:
* tHTTPd version 2.24
If you are using virtual hosting, and an attacker supplies a jiggered Host: header with ../.. in it, he can look at the top of the chroot tree. If you are not using chroot, he can browse your entire disk (You really should be using chroot.)