]> granicus.if.org Git - apache/commitdiff
Extra extra warnings.
authorCliff Woolley <jwoolley@apache.org>
Mon, 5 Aug 2002 20:11:32 +0000 (20:11 +0000)
committerCliff Woolley <jwoolley@apache.org>
Mon, 5 Aug 2002 20:11:32 +0000 (20:11 +0000)
Submitted by: Zeno <zeno@cgisecurity.net>

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@96311 13f79535-47bb-0310-9956-ffa450edef68

docs/manual/mod/mod_info.xml

index 0f5f6475c689d4c435d2a6eb7f59319c2c656dd6..16e2f7e86c5b729a963f972b82465c372a1d33fd 100644 (file)
@@ -48,6 +48,14 @@ SetHandler server-info<br />
       files, including <em>per</em>-directory files (<em>e.g.</em>,
       <code>.htaccess</code>). This may have security-related
       ramifications for your site.</p>
+
+      <p>In particular, this module can leak sensitive information
+      from the configuration directives of other Apache modules such as
+      system paths, usernames/passwords, database names, etc.  Due to
+      the way this module works there is no way to block information
+      from it.  Therefore, this module should ONLY be used in a controlled
+      environment and always with caution.</p>
+
     </note>
 </summary>