Joomla! 2.0.0 RC2 and earlier are susceptible to local file inclusion in the eXtplorer module (com_extplorer) that allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter in a show_error action.
View the template here CVE-2008-4764.yaml
References:
https://www.exploit-db.com/exploits/5435