Changes between Version 1 and Version 2 of Ticket #19867, comment 5


Ignore:
Timestamp:
Feb 21, 2013, 2:33:41 AM (11 years ago)
Author:
Aymeric Augustin

Legend:

Unmodified
Added
Removed
Modified
  • Ticket #19867, comment 5

    v1 v2  
    1 On Apache, by default, `SERVER_NAME` in under the control of the client. See the docs for [http://httpd.apache.org/docs/2.4/en/mod/core.html#usecanonicalname UseCanonicalName]:
     1On Apache, by default, `SERVER_NAME` in under the control of the client. See the docs for [http://httpd.apache.org/docs/2.4/en/mod/core.html#usecanonicalname UseCanonicalName], which is Off (the insecure value) by default:
    22>The CGI variables SERVER_NAME and SERVER_PORT will be constructed from the client supplied values as well.
    33
Back to Top