From e5c686b11af4879f0d94b3485a980525cfbcbf97 Mon Sep 17 00:00:00 2001 From: Guenter Knauf Date: Mon, 17 Dec 2012 21:53:16 +0000 Subject: [PATCH] Added comment. git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.4.x@1423173 13f79535-47bb-0310-9956-ffa450edef68 --- STATUS | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/STATUS b/STATUS index fb7cbf9360..2cb56b871f 100644 --- a/STATUS +++ b/STATUS @@ -167,6 +167,10 @@ PATCHES PROPOSED TO BACKPORT FROM TRUNK: of those two groups) who don't understand that these are information leaks once they are enabled, and the subtlety of the way they are disabled ("Apache messed up the first line; let me fix that") contributes to that. + fuankg notes: I've just added a big warning to all CGI scripts which should now + make alsolutely clear that these CGIs are for testing purpose only - so those + who enable those scripts with inserting the right shebang should be 100% aware + of any risks (this should cover your last point). A list of further possible backports can be found at: http://people.apache.org/~rjung/patches/possible-backports-httpd-trunk-2_4.txt -- 2.40.0