Hello There is a big back door on phpwcms project that can execute a plain text as a PHP (the url is passed as GET parameter). Read more here http://cesarodas.com/2007/08/how-to-avoid-hacker-attack-through-phpwcms.html -- Cesar D. Rodas http://www.cesarodas.com/ Mobile Phone: 595 961 974165 Phone: 595 21 645590 saddor@xxxxxxxxx saddor@xxxxxxxxxxxx [Non-text portions of this message have been removed]