How PHP is parsed is not at issue. Exposing the directory structure of the server machine is, however. This information can give insights about how the IIS web server is set up to someone with the right knowledge (or the wrong knowledge, depending on your pov). For example, if the permissions are not set correctly, knowing the path to certain IIS folders can allow an intruder to place his own web pages on your server, store illegal warez/porn, or just modify stuff.