httpd (attack vector):
CGI scripts are likely affected by this issue: when a CGI script is run by the web server, it uses environment variables to pass data to the script. These environment variables can be controlled by the attacker. If the CGI script calls Bash, the script could execute arbitrary code as the httpd user. mod_php, mod_perl, and mod_python do not use environment variables and we believe they are not affected.
mod_php non è vulnerabile a CVE-2014-6271 e CVE-2014-7169 perché non utilizza le variabili di ambiente. mod_fcgid 2.x usa le variabili d'ambiente?