This is a must read if you’re a pen tester or PHP developer.  Some great things on PHP security including file include, upload vulnerabilities, command execution, and of course SQL injection…

Assault on PHP Applications

Blackhat Forums

Author: Aelphaeis Mangarae

Date: June 13, 2009