Hello,
as we talk about it; the server should be hardened anyway.
It supports HTTP TRACE what shouldn't be allowed (can be used as kind of cross site scripting) and e.g. info.php is reachable aswell and telling a lot of things about the system. Just for example; Im not going to test the server without permission

Sen