[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [cobalt-users] CGI bin directory outside document root
- Subject: RE: [cobalt-users] CGI bin directory outside document root
- From: "Dan Kriwitsky" <webhosting@xxxxxxxxx>
- Date: Tue Apr 17 00:30:02 2001
- List-id: Mailing list for users to share thoughts on Cobalt products. <cobalt-users.list.cobalt.com>
> > My Raq is even worse in that it allows execution of a script from any
> > directory.
>
> All RaQs do that by default if you have CGI support enabled for a site.
>
IMO, it's a Good Thing?. Scripts shouldn't be vulnerable in the /web
directory. Configure the script so that any data files it writes to are
above /web so they can't be directly accessed.
--
Dan Kriwitsky