9.2. Security Considerations

SSI directives are as secure as you are. Don’t execute any commands that might do bad things or provide too much information. We suggest that directives like this not be included:

<!--#exec cmd="/bin/cat /etc/passwd"--> 

On the other hand, SSI doesn’t let the client do anything not specifically allowed by the server, so it’s relatively harmless. But don’t do anything stupid, anyway.

Get Open Source Web Development with LAMP: Using Linux, Apache, MySQL, Perl, and PHP now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.