This bug can be triggered remotely by sending a carefully crafted invalid request. This functionality is enabled by default.
hmm i dont know bout this but if this is true then i guess we have our temp solution here guys..

JP, AO is running on apache right??