*) SECURITY: Close a path-revealing exposure in multiview type map negotiation (such as the default error documents) where the module would report the full path of the typemapped .var file when multiple documents or no documents could be served based on the mime negotiation. *) SECURITY: Close a path-revealing exposure in cgi/cgid when we fail to invoke a script. The modules would report "couldn't create child process /path-to-script/script.pl" revealing the full path of the script.
If that is the case, then should whereami.asp be included with snitz?
that really depends on the server, if it is set up coorectly with the relevat permissions, revealing the physical location of the directory is not a security issue