  1. Blown totally out of proportion in regards the structure. Without direct terminal access apart from slack code in cgi scripts maybe php (exploit word press and inject into wordpress cron maybe?)
  3. Thats why this is maybe overblown (it takes an exploit to run an exploit, script injection (bad php exec))
  5. IMHO it would need an exploit to run the shellshock, Im not so sure on embedded stuff though and mobile (rooted devices, un-monitored app stores)
