That doesn't seem like a terribly sophisticated script.
It would be rather strange & disappointing if it does indeed let someone suck up a permissions restricted file off a LSWS server, and perhaps set up the attacker to do even more.
I'm interested too, just enabled mod_security first time ever ;-)
Due to monthly cost - or yearly I'm shocked this hasn't been patched up yet or announced by LiteSpeed, though I do understand it's weekend should someone give then a ring a ding?
I've not had a single issue that I can point out that is with 4.0.14, I used 4.0.13 for a few days or so when we fire'd up LiteSpeed on our cpanel box may 29th and back around Feb, .14 just seemed better