Currently, the PHP CGI binary returns an 500 error with a security message.
Best guess is cgi.force_redirect enabled. Apache logged only the first line, so I don't have the full message, only the Security! heading.
Settings should be added to /opt/php/lib/php.ini (yes lib instead of etc is rather queer).