Accipiter Direct AdServer is "responsible for advertisement handling for badge and banner ads as well as advertisement tracking. The Direct server acts as an http server listening for specially formed requests. It is a proprietary system and cannot be disabled".
A security vulnerability has been found in Accipiter Direct Server 6 that allows retrieval of arbitrary files.
Credit:
The information has been provided by Bassett, Mark.
Vulnerable systems:
* Accipiter Direct AdServer version 6.0
Arbitrary files can be viewed by using the exploit detailed below. Attacker traverses the HTTP server and retrieves arbitrary files by sending specially formed requests through a web browser.
Exploit:
By using the following URL, a remote attacker can access the boot.ini file under the Windows operating system: http://accipiterserver/%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cboot.ini
Workaround:
Vendor will be providing a patch with the next major release. Until then you may run your Accipiter Direct AdServer as an unprivileged user restricted to the webroot.