The following reply was made to PR mod_cgi/543; it has been noted by GNATS.
From: Mohit Aron <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Cc: Subject: Re: mod_cgi/543: "%2F" not allowed in VGI script PATH_INFO
Date: Sun, 27 Dec 1998 18:21:58 -0600 (CST)
Hi,
I have already posted this as incident 3589. Please look that up
to see what I want to say on this issue.
I manage the Dienst software at Rice Univ. I'm willing to live with a
somewhat slower Apache that also performs access checks after unescaping
the URL. Can this be provided as a configuration option in the next release
of Apache. Of course the correct behavior would be to do all access checks
after unescaping the URL.
- Mohit