nginx 0day exploit for nginx + fastcgi PHP

Ian Evans ianevans at digitalhit.com
Fri May 21 22:26:31 MSD 2010


Is this situation only pertaining to sites that allow uploads from forms?

Going way back to this thread
(http://www.ruby-forum.com/topic/145358#645652) in '08, I needed
cgi.fix-pathinfo=1 to fix problems with paths and specific extensionless
files I needed run as php.

Changing cgi.fix-pathinfo=1 to 0 broke a lot of stuff.






More information about the nginx mailing list