nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary files via the id parameter submitted to comm.php and the var_filename parameter submitted to viewrq.php.
View the template here CVE-2008-6668.yaml
References:
https://exchange.xforce.ibmcloud.com/vulnerabilities/43172