The point is that, when bash was written, there were few mechanisms for executing code as another user. There were servers/daemons, but they did not execute user code.
Of course some people would pipe to shell in their .forward file and eventually get pwnt, but it was a freshman mistake, and the damage was isolated.
Once you reach the point of executing a shell with an euid other than your own, it's not the shell's job to sanity check your actions.
The web has changed the execution model thoroughly. And people now do lazy things based on their loose understanding of flexible execution models.
This is neither a bug in bash, nor a bug in Apache, etc. It's an integration bug between two complex systems that were designed with zero-to-poor knowledge of each other.