"In the wild" in this case was just their honeypots. Actually vulnerable site should be very rare.
Also, one would assume that any website still using php-cgi has plenty of other security vulnerabilities.
Also, one would assume that any website still using php-cgi has plenty of other security vulnerabilities.
I would be surprised if these systems haven't already been p0wned a long time ago.
I bet there are still tens of thousands of otherwise secure php-cgi setups out there.