Hi. There is a brown-paper-bag bug in mathopd-1.5. So I have zapped that
release and put up mathopd-1.5p1 instead. If you run 1.5 please upgrade
ASAP. If you cannot upgrade you should at least define a global
Error404File (and an Error403File or Error401File if you use Access or
Realm.)

Thanks to Tahd Dell for pointing this out.

Problem description: normally requests for things like
/../../../../etc/passwd should be denied of course. Unfortunately the
introduction of CGI scripts for ErrorFiles ignored this check. :(

Sorry about this. Now I will go and stand in a corner for a month or so.

Reply via email to