billabongrob
Sammie, you do realize that you can turn off register globals in the .htaccess file, right?
robertsearle
Yes you can, however, that only turns it off on that one website in a shared hosting enviroment.

I believe the server can be configured as to what is allowed in the local .htaccess files.

As mentioned, once a site is hacked all sites on the server are accessible. Even if your hostheader website is protected it is accessible from another website on the same server. It really needs turned off at the server level or you should consider changing your hosting provider.

If register globals can see more be turned off, it is reasonable to assume register globals can be turned on. So one hostheader/virtual website can compromise security for the rest of the shared hosting server.

I just left my last hosting company because a poorly written ComDEV photo album application kept getting exploited. It turned out my clients competitor signed up for multiple accounts until they landed on the same server their site was on.
 
 
Below is the legacy version of the Boonex site, maintained for Dolphin.Pro 7.x support.
The new Dolphin solution is powered by UNA Community Management System.
PET:0.043426036834717