Try following the directions from this post. If it works, we have some more work to do on the development side. We added some features to attempt to clean the PHP_SELF variable to stop possible XSS hack attempts, but the solution I came up with may be causing the issue. If so, I'll have to rework the paths to make it universal (I'm guessing that's where the php.cgi is coming from if your server is running PHP as a FastCGI component).