Return-Path: Delivered-To: apmail-httpd-bugs-archive@www.apache.org Received: (qmail 86126 invoked from network); 13 Apr 2006 19:03:29 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (209.237.227.199) by minotaur.apache.org with SMTP; 13 Apr 2006 19:03:29 -0000 Received: (qmail 55485 invoked by uid 500); 13 Apr 2006 19:03:27 -0000 Delivered-To: apmail-httpd-bugs-archive@httpd.apache.org Received: (qmail 55404 invoked by uid 500); 13 Apr 2006 19:03:27 -0000 Mailing-List: contact bugs-help@httpd.apache.org; run by ezmlm Precedence: bulk List-Post: List-Help: List-Unsubscribe: Reply-To: "Apache HTTPD Bugs Notification List" List-Id: Delivered-To: mailing list bugs@httpd.apache.org Received: (qmail 55391 invoked by uid 99); 13 Apr 2006 19:03:27 -0000 Received: from asf.osuosl.org (HELO asf.osuosl.org) (140.211.166.49) by apache.org (qpsmtpd/0.29) with ESMTP; Thu, 13 Apr 2006 12:03:27 -0700 X-ASF-Spam-Status: No, hits=-9.4 required=10.0 tests=ALL_TRUSTED,NO_REAL_NAME X-Spam-Check-By: apache.org Received: from [209.237.227.198] (HELO brutus.apache.org) (209.237.227.198) by apache.org (qpsmtpd/0.29) with ESMTP; Thu, 13 Apr 2006 12:03:26 -0700 Received: by brutus.apache.org (Postfix, from userid 33) id AA3DB71428A; Thu, 13 Apr 2006 19:02:35 +0000 (GMT) From: bugzilla@apache.org To: bugs@httpd.apache.org Subject: DO NOT REPLY [Bug 39306] New: - Documentation for ScriptInterpreterSource is not specific enough Message-ID: X-Bugzilla-Reason: AssignedTo Date: Thu, 13 Apr 2006 19:02:35 +0000 (GMT) X-Virus-Checked: Checked by ClamAV on apache.org X-Spam-Rating: minotaur.apache.org 1.6.2 0/1000/N DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG� RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT . ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND� INSERTED IN THE BUG DATABASE. http://issues.apache.org/bugzilla/show_bug.cgi?id=39306 Summary: Documentation for ScriptInterpreterSource is not specific enough Product: Apache httpd-2 Version: 2.2-HEAD Platform: PC URL: http://httpd.apache.org/docs/2.2/mod/core.html#scriptint erpretersource OS/Version: Windows Server 2003 Status: NEW Severity: normal Priority: P3 Component: Documentation AssignedTo: bugs@httpd.apache.org ReportedBy: brett-hunsaker@automation-software.com The description of the Registry and Registry-Strict parameters is imprecise when it references which registry value is used. The current implementation uses the (Default) value of the key. MightI suggest the following description: Setting ScriptInterpreterSource Registry will cause the Windows Registry tree HKEY_CLASSES_ROOT to be searched using the script file extension (e.g., .pl) as a search key. The command defined by the default value of the registry subkey Shell\ExecCGI\Command or, if it does not exist, by the default value of the subkey Shell\Open\Command is used to open the script file. If the registry keys cannot be found, Apache falls back to the behavior of the Script option. For example, the registry setting to have a script with the .pl extension processed via perl would be: HKEY_CLASSES_ROOT\.pl\Shell\ExecCGI\Command\(Default) => C:\Perl\bin\perl.exe - wT Security Be careful when using ScriptInterpreterSource Registry with ScriptAlias'ed directories, because Apache will try to execute every file within this directory. The Registry setting may cause undesired program calls on files which are typically not executed. For example, the default open command on .htm files on most Windows systems will execute Microsoft Internet Explorer, so any HTTP request for an .htm file existing within the script directory would start the browser in the background on the server. This is a good way to crash your system within a minute or so. The option Registry-Strict which is new in Apache 2.0 does the same thing as Registry but uses only the default value of the subkey Shell\ExecCGI\Command. The ExecCGI key is not a common one. It must be configured manually in the windows registry and hence prevents accidental program calls on your system. -- Configure bugmail: http://issues.apache.org/bugzilla/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are the assignee for the bug, or are watching the assignee. --------------------------------------------------------------------- To unsubscribe, e-mail: bugs-unsubscribe@httpd.apache.org For additional commands, e-mail: bugs-help@httpd.apache.org