httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Lucid <lu...@secret.org>
Subject Re: Server parsed HTML bug!! (?)
Date Fri, 14 Jun 1996 02:36:35 GMT
> 
> On Thu, 13 Jun 1996, Rob Hartill wrote:
> > > I am trying to use a cgi script to generate Server parsed html
> > > The cgi script send the magic mimetype 
> > > Content-type: text/x-server-parsed-html
> > > 
> > > But It doesn't work, but It used to...
> > > Anyways I think it's a bug...
> > 
> > Never has been allowed in Apache or NCSA  AFAIK.
> > 
> > I tell people that it's a big security headache to allow it
> > 'cos few people can write secure enough CGI to prevent an
> > attacker from exploiting CGI which will execute things you
> > send it.
> > 
> > Sorry, no matches for search request:  <!--#exec cmd="cat /etc/passwd" -->
> > Please try again.
> 
> No, wait - I think he means that he wants to have a CGI script output HTML
> which would then be parsed by the server-side-include engine.  As far as
> I'm aware that has never been allowed - does NCSA 1.5 have that now or
> something?  The reason is because there is no internal pipelining
> mechanism in Apache - you can't tell one module to act on the output of
> another in this fashion.  At least as far as I'm aware.
> 
> 	Brian
> 
> --=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--
> brian@organic.com  www.apache.org  hyperreal.com  http://www.organic.com/JOBS
> 
> 

I used to work in Apache... I  understand why it doesn't work
but I wish it would work again... heres why.

I have an error script that generates the HTML for the error messages

/cgi-bin/error.cgi?type=404

It needs to dynamicaly build Server parsed HTML pages
I can work around the problem by adding the other scripts
and HTML It needs to access into the main script but
the code would be much more modular if I didnt have to...

any ideas?
-bill

Mime
View raw message