Details
Description
The following URLs allow a client to obtain resources from the file system that should not be exposed to the network:
http://auctionmonitor.icefaces.org/auctionMonitor/xmlhttp/%c0%af../WEB-INF/web.xml
http://component-showcase.icefaces.org/component-showcase/xmlhttp/%c0%af../WEB-INF/web.xml
Activity
- All
- Comments
- History
- Activity
- Remote Attachments
- Subversion
Adjust the regular expression used for serving files.