Last modified: 2010-05-15 15:28:18 UTC
The $wgFileBlacklist variable in DefaultSettings.php should include 'cgi', since those kinds of files may run arbitrary code (just like php or pl)
Fixed in CVS HEAD and REL1_3.