I can speak for CF6.0 upgrade to 6.1 on Window OS (XP).  The default for directory browsing is set to TRUE.  Why the hell, in this day and this hour, would a company has no concern about security or does not seem to think in the interest of its customers?

Before upgrade, yes, my box was set to disallow directory browsing after upgrade its changes my setting without notification.

Wish Allaire staff are still there.

Yours truly,

an upset customer
P.S. For those who wants to check it out and fix the security hole, look for
CFinstallationRoot\runtime\servers\default\SERVER-INF\default-web.xml

Please don't tell me to read doc crap, thank you.
[Todays Threads] [This Message] [Subscription] [Fast Unsubscribe] [User Settings]

Reply via email to