Microsoft's FrontPage 98 server side extensions for Apache under Unix
include a small setuid root program (fpexe) to allow the FrontPage CGIs to
be run as the user who owns the pages as opposed to them all running as
the user the web server runs as. This is necessary to get around gaping
loopholes that occur when all FrontPage documents are owned by the user
the web server runs as.
There are, however, gaping holes in this fpexe program that make it easily
exploitable to eventually gain root.
This is only in the FrontPage 98 extensions and is only in the Apache
version; it is completely unrelated to any Apache code and only occurs in
the Apache version simply because that is the only version where this
functionality is provided.
Details are at http://www.worldgate.com/~marcs/fp/