PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/7362
http://docs.iplanet.com/docs/manuals/pubx/2.5.2_Relnotes.html