I mean with a jsp code you can see/write file can a user write outside the
webapps defined in the server.xml? i ask this because i have already a
server with customer that with a simple jsp code write file into the conf or
bin directory (and the user was under a webapps)
How would that "simple jsp code" get into your webapps? Do you allow
any user to dump arbitrary code into your system?
BTW, tomcat-users.xml must also be writeable by Tomcat.
>- Chuck
THIS COMMUNICATION MAY CONTAIN CONFIDENTIAL AND/OR OTHERWISE PROPRIETARY
MATERIAL and is thus for use only by the intended recipient. If you
received this in error, please contact the sender and delete the e-mail
and its attachments from all computers.
---------------------------------------------------------------------
To start a new topic, e-mail: users@tomcat.apache.org
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]
---------------------------------------------------------------------
To start a new topic, e-mail: users@tomcat.apache.org
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]