> That's not allowed by the Policy to put non-cgi files in a cgi location,
> which is understandable I suppose :)

Out of curiosity (I know I'm going way offtopic here) why are php files 
allowed outside of cgi-bin?  :)  They can do just as much damage as 
other cgi scripts.  If it's the fact that they're actually interpreted 
by Apache instead of shelling out to them, would running Bugzilla under 
mod_perl let us put the files outside of cgi-bin?  mod_perl is just like 
mod_php in that regard.  (Bugzilla doesn't run under mod_perl yet, but 
it will one of these days)

I note that the mailman package has a /var/lib/mailman/cgi-bin, which is 
symlinked from /usr/lib/cgi-bin/mailman.

