Yes I have the correct files, but I changed it anyway based on a post I read on Apache Security. and changed the ini file. I'm re-running the scan now. I finally got all the errors out of the front end, but the admin is a disaster and will take hours to clean up.
I know I've been advised here turning error reporting off does the trick, but I had white screens, until I edited a slew of files.
The admin doesn't hide the errors...it won't let me even enter the admin itself until I fix them all. Thank gosh I didn't touch production site until I verified this all in my test enviornment - I would be in a total panic. As it is, when I've got the test version error free, then I'll take the site down, recompile and build in the new changes.
I'm running the scan again with your suggestions, but up till now the bot seems to be able to get to see everything.
I had to completely pull out and rebuild the blog I had integrated in order to upgrade that to the latest release, which wasn't fun, but got it done and then recompiled to 5.2.12, as I was originally told that would satisfy them, then they sent me another failed report saying nope...gotta to to 5.3.2 -
I think I want a new job...LOL :dontgetit