Yes, you need to enable 'write' permissions for all and no, this doesn't open you up to attacks as people still need a username and password to transfer files.
I have got a site running on Catalogue version 6 and have imported the snapshot into Business Version 8, made all of the changes that I want and then when I Test the Network setup' (all of the details are identical to the catalogue version) I get the 'You do not have write permissions to the cgi-bin directory "/public/www/cgi-bin/" or it does not exist.' error message.
Comment