Kaydet (Commit) 50324a60 authored tarafından Alex Martelli's avatar Alex Martelli

Avoid giving advice that's bad for security, as per SF bug #823515

(same as commit of Sun Nov 2 to the release23-maint branch)
üst 35d8360b
......@@ -598,7 +598,9 @@ Usually, this means using absolute path names --- \envvar{PATH} is
usually not set to a very useful value in a CGI script.
\item When reading or writing external files, make sure they can be read
or written by every user on the system.
or written by the userid under which your CGI script will be running:
this is typically the userid under which the web server is running, or some
explicitly specified userid for a web server's \samp{suexec} feature.
\item Don't try to give a CGI script a set-uid mode. This doesn't work on
most systems, and is a security liability as well.
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment