Not accurately as it depends how your server is configured, whether it uses CGI or not etc.
But broadly speaking everything should simply have full public (global) Read access not Write. Only one folder “/data” needs to have Write access. That is explained in http://wiki.webtrees.net/en/Security