Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls the phpinfo function.Referenceshttp://www.exploit-db.com/exploits/9490