I have a PHP file manager script but when I go to the script in firefox I notice I can see all the files I have on the server instead of just the directory the file is in, is this my server have bad security problem?
Sounds like bad security. Whole server is not a good idea. check your service account permissions.
GS RichCopy 360 Enterprise - Voted #1 for data migration and replication in terms of performance and features. Replicate data across between servers in the same network, WAS, or even across the internet
Is it the *whole* server or just the files for your account? If it is for the whole server, I advise that you contact your host immediately and warn them about any security risk (and I wouldn't be too sure with sticking with them, as who knows where else they may be failing in security, although this could have just slipped through the cracks).
If it is for your whole account, it may be a settings/poorly written php script, etc..