Hello!
Miniwebsvr 0.0.6 suffers from a directory traversal flaw.
"Exploit" :
http://yoursite/..%00
Attack vector seems limited as you're only able to list one level down.
Cheers,
Daniel Nystrm, daniel.nystrom (at) xored (dot) net [email concealed]
Fredrik Wessberg, fredd3 (at) hotmail (dot) com [email concealed]