While this is a bad thing to do, perhaps posting the link to it and making it even easier for people to find is worse? You probably should have just shown a snip, with the IP, etc blurred out or removed...
Having problems, or maybe questions about WHT? Head over to the help desk!
Yes, this is a bit odd. You can always remove the function instead, so you don't have to worry about this issue.
CybexHost.com - Shared and Reseller Hosting Solutions on cPanel/WHM Linux Servers ModernTweak.com - Discount ModernBill Licenses, Hosted Installations, and Professional Services :: Pay for your discount ModernBill license with PayPal :: admin[at]cybexhost.com :: AIM: CybexH
Huh? I'm confused. This isn't leaking important information to the *world*. It's only leaking it to the programmer writing the .php scripts. And nearly all of that information being 'leaked' is incredibly useful and necessary when writing PHP scripts. phpinfo() is not something that should ever be left lying around for random people to run. It's not insecure as such, it just discloses more information about your web server than is sensible.
Oh, and if the world can put PHP scripts on your server when they feel like it, you've got much bigger problems than this!!
And yes, in a shared hosting environment, it is easy for someone to get access to some of your data, especially if your shared environnment doesn't use suexec/phpsuexec. However, if your files are correctly protected, it's fairly difficult for them to do it, and if your data is in a MySQL database, it's considerably more difficult. The point is, there is no such thing as "perfectly secure", anything that is that secure is generally highly complex and really unuseable. One example was a bank that was using a vendor built security gateway to run some of their code. It was so complex that none of the development or admin staff understood it and in the end it was only used for a short time and then discarded. Even on a non-shared server, if a smart hacker is determined enough your data will be readable. You just need to make it hard enough to discourage casual attackers, take great backups, and keep your machines up to date with patches, and not antagonize smart hackers, and you should be fine!