On Sun, 19 Aug 2001, Deacon Marcus wrote:

> Hi,
> 
> > -----Original Message-----
> > From: Pier P. Fumagalli [mailto:[EMAIL PROTECTED]]
> > Sent: Saturday, August 18, 2001 10:44 AM
> > To: tomcat dev jakarta.apache.org
> > Subject: CGI wrapper in Tomcat 4.0 b7
> >
> [...]
> >
> > (BTW, wouldn't it be wise to disable CGI execution in the default
> > configuration? I don't know, after hearing people running Tomcat
> > as root, I
> > feel we really should!)
> 
> You mean it's _enabled_ by _default_ ??
> /me is running to his server's console to immediately disable CGI before one
> of his customers find out it's enabled and it's too late ;/
> 

It's enabled by default for CGI scripts *inside* your web app, whose
context relative URI paths match "/cgi-bin/*" and where the corresponding
files are under "/WEB-INF/cgi".  Have any of those?

> Greetings, deacon Marcus
> 
> 
> 
> 
Craig (who is amused by this, since Apache itself ships with CGI enabled)



Reply via email to