You're absolutely right, nebulus200 and swarisd! After a quick search, I came across this:

http://www.kbeta.com/attacklist/HTTP_Shells.htm

Who would be silly enough to put shell interpreters in the cgi-bin directory? I could run anything I want on your box from the web! Thanks for catching my goof, guys.

Here's the link to the whole list of attack descriptions:

http://www.kbeta.com/attacklist/Real...%20Decodes.htm