MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other parameter, which reveals the installation path in an error message.
https://exchange.xforce.ibmcloud.com/vulnerabilities/11556
https://euvd.enisa.europa.eu/vulnerability/EUVD-2003-1538
http://www.securitytracker.com/id?1006308
http://www.securityfocus.com/bid/7126
http://www.securityfocus.com/archive/1/315317/30/25460/threaded