phpBB 2.0.13 and earlier allows remote attackers to obtain sensitive information via a direct request to oracle.php, which reveals the path in a PHP error message.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-0660
http://securitytracker.com/id?1013377
http://neosecurityteam.tk/index.php?pagina=advisories&id=9