[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] CGI bin directory outside document root



> > My Raq is even worse in that it allows execution of a script from any
> > directory.
>
> All RaQs do that by default if you have CGI support enabled for a site.
>
IMO, it's a Good Thing?. Scripts shouldn't be vulnerable in the /web
directory. Configure the script so that any data files it writes to are
above /web so they can't be directly accessed.
--
Dan Kriwitsky