Welcome! Log In Create A New Profile

Advanced

Re: nginx 0day exploit for nginx + fastcgi PHP

May 21, 2010 09:34PM
Yeah I've always had it set to 1 too. I think fastcgi_split_path_info
may be able to bridge the gap perhaps.

On May 21, 2010, at 6:17 PM, Grzegorz Sienko <staff@krecio.pl> wrote:

>> From php.ini
>
> ; previous behaviour was to set PATH_TRANSLATED to SCRIPT_FILENAME,
> and to not grok
> ; what PATH_INFO is. For more information on PATH_INFO, see the cgi
> specs. Setting
> ; this to 1 will cause PHP CGI to fix it's paths to conform to the
> spec. A setting
> ; of zero causes PHP to behave as before. Default is 1. You should
> fix your scripts
> ; to use SCRIPT_FILENAME rather than PATH_TRANSLATED.
> cgi.fix_pathinfo=1
>
>
> 2010/5/22 Cliff Wells <cliff@develix.com>:
>> On Fri, 2010-05-21 at 10:48 -0700, Michael Shadle wrote:
>>> Default is zero.
>>
>> Indeed.
>>
>> I can't find a single installation of PHP (amongst about 35 virtual
>> servers I checked) where this option isn't commented out (so
>> defaulting
>> to 0).
>>
>> Is there some widely-used PHP application that requires this be on?
>>
>> Cliff
>>
>> --
>>
>>
>> _______________________________________________
>> nginx mailing list
>> nginx@nginx.org
>> http://nginx.org/mailman/listinfo/nginx
>>
>
> _______________________________________________
> nginx mailing list
> nginx@nginx.org
> http://nginx.org/mailman/listinfo/nginx

_______________________________________________
nginx mailing list
nginx@nginx.org
http://nginx.org/mailman/listinfo/nginx
SubjectAuthorPosted

nginx 0day exploit for nginx + fastcgi PHP

Avleen VigMay 21, 2010 01:14PM

Re: nginx 0day exploit for nginx + fastcgi PHP

Avleen VigMay 21, 2010 01:30PM

Re: nginx 0day exploit for nginx + fastcgi PHP

Eren TürkayMay 25, 2010 11:44AM

Re: nginx 0day exploit for nginx + fastcgi PHP

mikeMay 21, 2010 01:30PM

Re: nginx 0day exploit for nginx + fastcgi PHP

Igor SysoevMay 21, 2010 01:36PM

Re: nginx 0day exploit for nginx + fastcgi PHP

Igor SysoevMay 21, 2010 01:44PM

Re: nginx 0day exploit for nginx + fastcgi PHP

mikeMay 21, 2010 01:52PM

Re: nginx 0day exploit for nginx + fastcgi PHP

Igor SysoevMay 21, 2010 02:16PM

Re: nginx 0day exploit for nginx + fastcgi PHP

Ian EvansMay 21, 2010 02:30PM

Re: nginx 0day exploit for nginx + fastcgi PHP

mikeMay 21, 2010 02:40PM

Re: nginx 0day exploit for nginx + fastcgi PHP

Igor SysoevMay 21, 2010 02:40PM

Re: nginx 0day exploit for nginx + fastcgi PHP

Ian M. EvansMay 21, 2010 03:10PM

Re: nginx 0day exploit for nginx + fastcgi PHP

Igor SysoevMay 21, 2010 04:46PM

Re: nginx 0day exploit for nginx + fastcgi PHP

Ian EvansMay 21, 2010 04:58PM

Re: nginx 0day exploit for nginx + fastcgi PHP

Igor SysoevMay 21, 2010 05:20PM

Re: nginx 0day exploit for nginx + fastcgi PHP

Ian EvansMay 21, 2010 05:54PM

Re: nginx 0day exploit for nginx + fastcgi PHP

Igor SysoevMay 22, 2010 02:10AM

Re: nginx 0day exploit for nginx + fastcgi PHP

Ian M. EvansMay 22, 2010 01:28AM

Re: nginx 0day exploit for nginx + fastcgi PHP

Igor SysoevMay 22, 2010 01:32AM

Re: nginx 0day exploit for nginx + fastcgi PHP

Ian EvansMay 22, 2010 03:00AM

Re: nginx 0day exploit for nginx + fastcgi PHP

Igor SysoevMay 22, 2010 03:58AM

Re: nginx 0day exploit for nginx + fastcgi PHP

Ian M. EvansMay 22, 2010 05:46AM

Re: nginx 0day exploit for nginx + fastcgi PHP

Igor SysoevMay 22, 2010 06:12AM

Re: nginx 0day exploit for nginx + fastcgi PHP

Ian M. EvansMay 22, 2010 06:22AM

Re: nginx 0day exploit for nginx + fastcgi PHP

Igor SysoevMay 22, 2010 06:26AM

Re: nginx 0day exploit for nginx + fastcgi PHP

Ian M. EvansMay 22, 2010 06:56AM

Re: nginx 0day exploit for nginx + fastcgi PHP

Ian M. EvansMay 22, 2010 08:22AM

Re: nginx 0day exploit for nginx + fastcgi PHP

Igor SysoevMay 22, 2010 08:30AM

Re: nginx 0day exploit for nginx + fastcgi PHP

Ian M. EvansMay 22, 2010 08:48AM

Re: nginx 0day exploit for nginx + fastcgi PHP

Ian M. EvansMay 22, 2010 06:30PM

Re: nginx 0day exploit for nginx + fastcgi PHP

Jérôme LoyetMay 21, 2010 03:50PM

Re: nginx 0day exploit for nginx + fastcgi PHP

Weibin YaoMay 23, 2010 11:24PM

Re: nginx 0day exploit for nginx + fastcgi PHP

Jérôme LoyetMay 24, 2010 03:00AM

Re: nginx 0day exploit for nginx + fastcgi PHP

Weibin YaoMay 24, 2010 04:20AM

Re: nginx 0day exploit for nginx + fastcgi PHP

Cliff WellsMay 21, 2010 09:00PM

Re: nginx 0day exploit for nginx + fastcgi PHP

Grzegorz SienkoMay 21, 2010 09:24PM

Re: nginx 0day exploit for nginx + fastcgi PHP

mikeMay 21, 2010 09:34PM

Re: nginx 0day exploit for nginx + fastcgi PHP

gdorkJanuary 26, 2011 11:07PM

Re: nginx 0day exploit for nginx + fastcgi PHP

mikeJanuary 26, 2011 11:16PM

Re: nginx 0day exploit for nginx + fastcgi PHP

edogawaconanJanuary 27, 2011 12:28AM

Re: nginx 0day exploit for nginx + fastcgi PHP

mikeJanuary 27, 2011 01:08AM

Re: nginx 0day exploit for nginx + fastcgi PHP

Cliff WellsMay 21, 2010 10:42PM

Re: nginx 0day exploit for nginx + fastcgi PHP

Ding DengMay 22, 2010 09:28AM

Re: nginx 0day exploit for nginx + fastcgi PHP

mikeMay 22, 2010 03:30PM

Re: nginx 0day exploit for nginx + fastcgi PHP

brianmercerMay 21, 2010 05:03PM

Re: nginx 0day exploit for nginx + fastcgi PHP

tuurtntDecember 14, 2011 06:26PM

Re: nginx 0day exploit for nginx + fastcgi PHP

KraiserFebruary 17, 2012 09:53AM

Re: nginx 0day exploit for nginx + fastcgi PHP

Reinis RozitisFebruary 17, 2012 11:42AM

Re: nginx 0day exploit for nginx + fastcgi PHP

zseroOctober 30, 2012 01:01PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 107
Record Number of Users: 7 on March 06, 2014
Record Number of Guests: 184 on July 08, 2014
Powered by nginx    Powered by FreeBSD    PHP Powered    Powered by Percona     ipv6 ready