Partial Links 1.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) page_footer.php and (2) page_header.php, which displays the path in an error message.
https://exchange.xforce.ibmcloud.com/vulnerabilities/26956
http://www.vupen.com/english/advisories/2006/2169
http://www.securityfocus.com/archive/1/436112/100/0/threaded