Directory traversal vulnerability in server.np in NetPublish Server 7 allows remote attackers to read arbitrary files via "../" sequences in the template parameter.
http://www.vupen.com/english/advisories/2005/3045
http://www.extensis.com/en/support/kb_article.jsp?articleNumber=3302201