While I'm upgrading stuff anyway, at cvsweb.cgi, I see not "ini_restore" patch in files/ yet for this php4.4.4 exploit. As described in: http://securityreason.com/achievement_securityalert/42 Or is this done internally yet? Thanks, - Mark