RE: [SECURITY] Apache Tomcat 4.x JSP source disclosurevulnerabili ty

2002-09-25 Thread Felipe Schnack
Anyway, using scriptlets (JSP) is a bad pratice... good code uses only taglibs. On Wed, 2002-09-25 at 10:57, Rossen Raykov wrote: The servlets are not vulnerable since their code is under WEB-INF and is successfully protected from downloads. All other interpreted application stuff, outside

RE: [SECURITY] Apache Tomcat 4.x JSP source disclosurevulnerabili ty

2002-09-25 Thread Rob Reed
please let me know if you are still experiencing this. It looks correct to me right now. Thanks, Rob Reed Isomedia.com On Wed, 2002-09-25 at 14:28, Dan K. wrote: Hi. I've just confirmed that Velocity (at least in Turbine v2.1) suffers from this problem. Regards, Dan On Wed, 25 Sep