https://issues.apache.org/bugzilla/show_bug.cgi?id=53891
Priority: P2
Bug ID: 53891
Assignee: dev@tomcat.apache.org
Summary: Problem in Tomcat 6.x and 7.x Windows version permit
access to WEB-INF
Severity: major
Classification: Unclassified
OS: Windows XP
Reporter: marcos.rivera@intelygenz.com
Hardware: PC
Status: NEW
Version: unspecified
Component: Native:Integration
Product: Tomcat 6
Hi,
There is a problem with Tomcat 6.x / 7.x for Windows that allows access to the
WEB-INF folder when a "." is added at the end of WEB-INF in a URL
Example:
http://www.somedomain.com/WEB-INF./web.xml
--
You are receiving this mail because:
You are the assignee for the bug.
---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tomcat.apache.org
For additional commands, e-mail: dev-help@tomcat.apache.org
|