]> granicus.if.org Git - apache/commitdiff
Added comment.
authorGuenter Knauf <fuankg@apache.org>
Mon, 17 Dec 2012 21:53:16 +0000 (21:53 +0000)
committerGuenter Knauf <fuankg@apache.org>
Mon, 17 Dec 2012 21:53:16 +0000 (21:53 +0000)
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.4.x@1423173 13f79535-47bb-0310-9956-ffa450edef68

STATUS

diff --git a/STATUS b/STATUS
index fb7cbf9360aad61597f1f3a80d5e8978c15b1781..2cb56b871f1668e20dfd0423c5110f71cd577f34 100644 (file)
--- a/STATUS
+++ b/STATUS
@@ -167,6 +167,10 @@ PATCHES PROPOSED TO BACKPORT FROM TRUNK:
           of those two groups) who don't understand that these are information leaks
           once they are enabled, and the subtlety of the way they are disabled ("Apache
           messed up the first line; let me fix that") contributes to that.
+     fuankg notes: I've just added a big warning to all CGI scripts which should now
+          make alsolutely clear that these CGIs are for testing purpose only - so those
+          who enable those scripts with inserting the right shebang should be 100% aware
+          of any risks (this should cover your last point).
 
 A list of further possible backports can be found at:
     http://people.apache.org/~rjung/patches/possible-backports-httpd-trunk-2_4.txt