If a phpinfo()
dump is shown to an end user, what is the worst that a malicious user could do with that information? What fields are most unsecure? That is, if your phpinfo()
was publicly displayed, after taking it down, where should you watch/focus for malicious exploits?
I'm wiki'ing this up, so that we can compile answers.