Stack-based buffer overflow in the (1) putdir function in mongoose.c in Mongoose 3.0, (2) putdir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) shttpdputdir function in iodir.c in Simple HTTPD (shttpd) 1.42 allows remote attackers to execute arbitrary code via an HTTP PUT request, as exploited in the wild in 2011.