The (1) function.php or (2) function.view.php scripts in Merak Mail Server 5.2.7 allow remote attackers to read arbitrary PHP files via a direct HTTP request to port 32000.
https://exchange.xforce.ibmcloud.com/vulnerabilities/17029
http://www.securityfocus.com/bid/10966
http://securitytracker.com/id?1010969
http://secunia.com/advisories/12269