cat /home/clientXYZ/*.php
and you will probably screens php code from clientXYZ's folder.
I agree with the original author. Shared hosting extremely insecure.