It's possible to retrieve file from CGI-BIN directory by typing directory name uppercase (http://127.0.0.1/CGI-BIN/chat.pl)
vulners.com/securityvulns/securityvulns:doc:9952