By Seecr

Software Craftsmanship

Seecr - Software Craftsmanship A service by Seecr,
This site was last updated on March 22 2012

Changeset: fileserver-possible-exploit-solved

Title

Solves a possible exploit in FileServer

Description

The exploit found was that it was able to request paths outside the
given documentRoot, e.g. a path like '/../etc/resolv.conf' would
return the contents of '/etc/resolv.conf'.

Packages containing this changeset

meresco-components, meresco-core

Creation date

2010-08-12

Versions where this changeset is applied

Baseline version

meresco-components/workingsets/3.1.1-Edurep/version_1

Filename

201008121107.fileserver-possible-exploit-solved.changeset [download]