I ran across this site that shows an exploit of php that gives access to the php info as if they used a page with the phpinfo() function.
The reference is here http://perishablepress.com/expose-php/
I did test my site and it works....can you close this up please?
Sorry to throw another issue onto your pile but my site redash.org is reporting...
403 Forbidden
Access to this resource on the server is denied!
--------------------------------------------------------------------------------
Powered By LiteSpeed Web Server
LiteSpeed Technologies is not...