Is anyone here still running PHP using mod_cgi on Apache? If so, you need to read this: http://www.php.net/archive/2012.php#id2012-05-03-1
The vulnerability gives an attacker access to your source code, which may reveal database passwords or implementation details that lead to further, more serious attacks. Cheers, Chris Snyder http://chxor.chxo.com/ _______________________________________________ New York PHP User Group Community Talk Mailing List http://lists.nyphp.org/mailman/listinfo/talk http://www.nyphp.org/show-participation