Allaire Security Bulletin (ASB00- 27) : JRun 3.0: Patch Available for Extra Leading Slash Security Issue
Under certain circumstances, the included JRun 3.0 http server may improperly handle leading path-specifying characters and a deliberately malformed URI will allow browser access to otherwise-forbidden JRun 3.0 resources. Here's the patch:
Allaire Security Bulletin (ASB00-27) (Allaire Security Bulletin)