>It is now corrected in (11).

The following rules apply now:

- '..' unallowed everywhere

- Edit of files in ASSP directory OR upper directories allowed only
for 
'.txt' and '.db' files. This to block accessing to other info at the
assp 
directory, like assp.pl or even the config etc

- Get of ANY file at any upper directory like images or pb, but NOT at
the 
assp directory


-------------------------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642
_______________________________________________
Assp-user mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/assp-user

Reply via email to