A quick tour through the SecurityFocus vulnerability database and Bugtraq and a website like milw0rm reveals many PHP applications ripe for exploitation. Many require only very simple file inclusion exploits. And thats exactly why some people are exploiting them. Its the low-hanging fruit. It only takes a few minutes to understand a typical web applications coding errors and then search for vulnerable installations using Google. In just a few minutes, an average attacker with little talent and even less time can compromise a typical server.