ht://dig is a web content search engine for Unix platforms. The software is set up to allow for file inclusion from configuration files. Any string surrounded by the opening singlw quote character ( ` ) is taken as a path to a file for inclusion, for example:
htdig will also allow included files to be specified via form input. Therefore, any file can be specified for inclusion into a variable by any web user.
will return a page with the contents of /etc/passwd in the 'exclude' field.