Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the id parameter of the read module.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-4203
http://www.securityfocus.com/bid/15796
http://www.securityfocus.com/archive/1/419107/100/0/threaded