Re: Risk by allowing application* params

2014-08-08 Thread Lukasz Lenart
2014-08-07 11:43 GMT+02:00 Fabian Richter : > Hey, > > we are wondering why struts params interceptor excludes > > ^application\..* > > as a parameter? > > To what kind of vulernatbilities would we open our applications if we allow > parameters starting with application to be set by struts? It's t

Risk by allowing application* params

2014-08-07 Thread Fabian Richter
Hey, we are wondering why struts params interceptor excludes ^application\..* as a parameter? To what kind of vulernatbilities would we open our applications if we allow parameters starting with application to be set by struts? Thank you and best Fabian smime.p7s Description: S/MIME Cryp