No idea.<p>What is /cgi-bin/phf?<p>Why do you say it is a vulnerability?<p>You will probably get better quality answers if you ask on a Q+A site such as Server Fault, and include relevant background information (e.g. answers to my questions above).<p><a href="http://serverfault.com/questions/ask" rel="nofollow">http://serverfault.com/questions/ask</a>