PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/7362
https://euvd.enisa.europa.eu/vulnerability/EUVD-2000-1181
http://packetstormsecurity.org/0004-exploits/ooo1.txt
http://docs.iplanet.com/docs/manuals/pubx/2.5.2_Relnotes.html