A security issue has been discovered by Daniel de Rauglaudre, upstream
author of geneweb, a genealogical software with web interface. It runs as
a daemon on port 2317 by default. Paths are not properly sanitized, so a
carefully crafted URL leads geneweb to read and display arbitrary files of
the system it runs on.