Stumbled upon https://gist.github.com/anonymous/929d622f3b36b00c0be1
Just to verify; apache httpd / nginx without CGI-support is not vulnerable?
Just to verify; apache httpd / nginx without CGI-support is not vulnerable?
One way for that to happen is if your CGI-application runs things via os.system() / system(). It is not the web server itself that has the problem, nor any common CGI-setup (unless you write your CGI-scripts in bash, in which case you are guaranteed to have other problems).