WARNING: Be very careful editing your server configuration
or .htaccess files. Even a minor typographical error can
make your site unusable! Always make a backup copy of any file so you
can recover quickly.
I have noticed that since I have added INCLUDES to my .htaccess
file, or to my access.srm, that 'exec cmd=' works. This is sort
of scary from a security standpoint. What should I do???
To do this, you MUST have access to the master server
configuration files. If you are unable to edit these
files, ask your system administrator to do it for you.
If you do not have access to the server configuration files,
you can add this line to your .htaccess file.
IncludesNoExec
Edit the file access.conf file
and do the following:
Locate the container with your directory where the INCLUDES is located
and add the word: