This could possibly related to that I had Apache KeepAlive disabled:
http://tracker.vbulletin.com/browse/VBIV-7712
I have enabled KeepAlive now, and things like POST seem to work better with php-direct-eval but I have not dug into details yet.
--------------- Added [DATE]1303815211[/DATE] at [TIME]1303815211[/TIME] ---------------
I have done some more tests and it seems that both the POST problem and the security token issues where solved simply by enabling Apache KeepAlive (which is the default setting for Apache).