CVE-2008-4297
Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.
Date published : 2008-09-26
http://www.securityfocus.com/bid/31223
http://www.securityfocus.com/archive/1/496488/100/0/threaded