Yaws 1.91 allows unauthenticated local file inclusion via /%5C../ submitted to port 8080.
View the template here CVE-2017-10974.yaml
References:
http://hyp3rlinx.altervista.org/advisories/YAWS-WEB-SERVER-v1.91-UNAUTHENTICATED-REMOTE-FILE-DISCLOSURE.txt