summaryrefslogtreecommitdiffstats
path: root/docs/cgi-examples/printenv.wsf
diff options
context:
space:
mode:
authorGuenter Knauf <fuankg@apache.org>2012-12-17 22:44:32 +0100
committerGuenter Knauf <fuankg@apache.org>2012-12-17 22:44:32 +0100
commitf1e3cd4568591963d19220359f18f1a12c61b248 (patch)
tree5bb08a69527b43dd87311bcd670dc6bb2490a3dc /docs/cgi-examples/printenv.wsf
parentxforms (diff)
downloadapache2-f1e3cd4568591963d19220359f18f1a12c61b248.tar.xz
apache2-f1e3cd4568591963d19220359f18f1a12c61b248.zip
Added a warning that these scripts leak information.
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@1423166 13f79535-47bb-0310-9956-ffa450edef68
Diffstat (limited to 'docs/cgi-examples/printenv.wsf')
-rw-r--r--docs/cgi-examples/printenv.wsf9
1 files changed, 6 insertions, 3 deletions
diff --git a/docs/cgi-examples/printenv.wsf b/docs/cgi-examples/printenv.wsf
index c70b9a65c5..d982eac21f 100644
--- a/docs/cgi-examples/printenv.wsf
+++ b/docs/cgi-examples/printenv.wsf
@@ -3,9 +3,12 @@
' To permit this cgi, replace ' on the first line above with the
' appropriate shebang, f.e. '!c:/windows/system32/cscript -nologo
'
-' Note that it is subject to cross site scripting attacks on MS IE
-' and any other browser which fails to honor RFC2616, so never use
-' it in a live server environment, it is provided only for testing.
+' ***** !!! WARNING !!! *****
+' This script echoes the server environment variables and therefore
+' leaks information - so NEVER use it in a live server environment!
+' It is provided only for testing purpose.
+' Also note that it is subject to cross site scripting attacks on
+' MS IE and any other browser which fails to honor RFC2616.
''
'' printenv -- demo CGI program which just prints its environment