Installed as CGI binary

Possible attacks

Case 1 : only public files served

Case 2 : using --enable-force-cgi-redirect




Case 3 : setting doc_root or user_dir

Case 4 : PHP parser outside of web tree

as the first line of any file containing PHP tags. You will also need to make the file executable. That is, treat it exactly as you would treat any other CGI script written in Perl or sh or any other common scripting language which uses the #! shell-escape mechanism for launching itself.