Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of the filename in the page parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/18748
http://www.securityfocus.com/bid/12163
http://www.qwikiwiki.com/index.php?page=QwikiVulnerability