Unknown vulnerability in Sympoll 1.2 allows remote attackers to read arbitrary files when register_globals is enabled, possibly by modifying certain PHP variables through URL parameters.
http://www.securityfocus.com/bid/5360
http://www.ralusp.net/downloads/sympoll/changelog.txt
http://archives.neohapsis.com/archives/bugtraq/2002-07/0401.html