Description
The web server has several virtual hosts. Due to an incorrect configuration of virtual hosts, files of one virtual host is located inside a directory of another one. Therefore, an attacker may access parts of the source code of your web application.
Remediation
Change vitrual hosts configuration, so each of them have a separate root directory
References
Related Vulnerabilities
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1052)
WordPress Plugin Simple Download Monitor Multiple Vulnerabilities (3.9.5.1)
WordPress Plugin WordPress File Upload Multiple Vulnerabilities (2.7.6)
WordPress 4.0.x Multiple Vulnerabilities (4.0 - 4.0.11)
WordPress Plugin W3 Total Cache Information Disclosure (0.9.2.4)