httpd-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Ben Hyde <bh...@pobox.com>
Subject Re: cvs commit: apache-1.3/src/modules/standard mod_cgi.c
Date Sun, 01 Nov 1998 13:58:46 GMT
Marc Slemko writes:
>Thinking about it, this auto adding .EXE is just a bad scene
>and needs to be removed unless someone can justify it.  The problem
>is that it introduces a security hole; if someone protects
>"foo.exe", then someone can bypass that protection by using "foo".

+1 - ben

Mime
View raw message