Nonscript-aliased CGI

Allowing users to execute CGI scripts in any directory should only be considered if:

  • You trust your users not to write scripts that will deliberately or accidentally expose your system to an attack.

  • You consider security at your site to be so feeble in other areas as to make one more potential hole irrelevant.

  • You have no users, and nobody ever visits your server.

Get Apache: The Definitive Guide, 3rd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.