Upgrade to 4.1.2
| From: | C vd Veen | Date: | Mon, 18 Mar 2002 18:37:57 +0000 |
| Subject: | Upgrade to 4.1.2 | ||
| Groups: | php.install | ||
| Request: | Send a blank email to php-install+get-6402@lists.php.net to get a copy of this message | ||
Yesterday I upgraded PHP from 4.1.1 to 4.1.2, everything worked normal, untill I used Mysql.
This is what I get:
Security Alert! PHP CGI cannot be accessed directly.
This PHP CGI binary was compiled with force-cgi-redirect enabled. This means that a page will only
be served up if the REDIRECT_STATUS CGI variable is set. This variable is set, for example, by
Apache's Action directive redirect.
You may disable this restriction by recompiling the PHP binary with the --disable-force-cgi-redirect
switch. If you do this and you have your PHP CGI binary accessible somewhere in your web tree,
people will be able to circumvent .htaccess security by loading files through the PHP parser. A good
way around this is to define doc_root in your php.ini file to something other than your top-level
DOCUMENT_ROOT. This way you can separate the part of your web space which uses PHP from the normal
part using .htaccess security. If you do not have any .htaccess restrictions anywhere on your site
you can leave doc_root undefined. If you are running IIS, you may safely set cgi.force_redirect=0 in
php.ini
When I turn off the cgi.force_redirect function it works fine again, but I want to know if it is
save on a Xitami webserver running on a Windows 98 machine...
If someone knows... pls. help.
Thanks
--------------------------------------------------------------------------------
C van de Veen
captain-internet@hetnet.nl
http://www.baarnhosting.nl