Filters apply as you choose them.
CGI PHP mlog script allows an attacker to read any file on the target server.