Directory traversal vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to include and execute arbitrary local .jsp files, and obtain sensitive information, via a .. (dot dot) in the editor parameter.
https://www.exploit-db.com/exploits/5112
https://exchange.xforce.ibmcloud.com/vulnerabilities/40508
http://www.bugsec.com/articles.php?Security=48&Web-Application-Firewall=0