C definitely - strlen() not binary safe, you have to deal with malloc()/free()/strdup() etc. by hand instead of letting a highly optimized GC do the job...
Or you could just strdup and malloc a bunch of strings and let the kernel clean it up when the cgi process exits. ;)
Yes. C & C++ strings are so bad that most large libraries ship with their own string functions.