opendir.php script in PHP-Nuke allows remote attackers to read arbitrary files by specifying the filename as an argument to the requesturl parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/6512
https://euvd.enisa.europa.eu/vulnerability/EUVD-2001-0321
http://archives.neohapsis.com/archives/bugtraq/2001-02/0214.html