i don't think this is possible but can a function call be inserted into the URL and passed back the server, executed and the results passeed back to the client?
ie if i type in this...
site.com/index.php?show_source(index.php");
can i spoof the server into passing back the source of the page?