I have no idea what the status of the HTTP interface is... I have simply never used it. It's possible that login.cgi is a standard name like index.htm is and that it should authorize/deny the login. Presumably this would use the documented PHP ioftpd functions to access the user database... If anyone has the file speak up
Personally I have zero interest in working on this though if someone is interested I suggest you grab the 6.1 sourcecode I released and take a look at what's going on... At least you would know what's expected of login.cgi