PHP-Fusion version 4.00 has a full path disclosure vulnerability and a flaw that allows an attacker to download the database backup file that can be used to gain administrative access.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/34092/adv04-y3dips-2004.txt
Source: https://packetstormsecurity.com/files/34092/Echo-Security-Advisory-2004.4.html

