FormHandler.cgi uses hard coded physical path names for templates so it is possible to read any file on the system.