If you use PHP, you can add the following to php.ini to mitigate risks like these (mitigate != bulletproof) :
; Mayhem dropper uses "system" so let's kill that and other dangerous functions
disable_functions = system,eval,curl_exec,curl_multi_exec,exec,passthru,shell_exec,show_source
If this breaks your software, your software is badly written.Allowing write permissions in the script directory is always a dangerous thing. It's best to put the application files outside root and enable execute permissions only on the script directory. If uploading files is allowed, it should be to read/write enabled directories only. Execute permissions should be turned off.
The dropper tries to kill critical processes as mentioned so chrooting services individually is a good idea.
Or you could just use OpenBSD ;-)