Some versions of vqSoft vqServer for Windows are vulnerable to the common ../../ method of retrieving known files from outside of the web directory structure, accomplished by appending a variable number of "../" and a known filename to an HTTP GET request.
vqSoft VqServer URI Traversal Arbitrary File Access
Remote / Network Access
Loss of Integrity
vqSoft vqServer contains a flaw that allows a remote attacker to view arbitrary files outside of the web path. The issue is due to the server not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the URI.
Upgrade to version 1.9.31 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.