www-apache-bugdb mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From c...@apache.org
Subject Re: mod_negotiation/1053: "Negotiated" DirectoryIndex file listed in error if inaccessible
Date Tue, 29 Sep 1998 14:52:10 GMT
[In order for any reply to be added to the PR database, ]
[you need to include <apbugs@Apache.Org> in the Cc line ]
[and leave the subject line UNCHANGED.  This is not done]
[automatically because of the potential for mail loops. ]
[If you do not include this Cc, your reply may be ig-   ]
[nored unless you are responding to an explicit request ]
[from a developer.                                      ]
[Reply only with text; DO NOT SEND ATTACHMENTS!         ]

Synopsis: "Negotiated" DirectoryIndex file listed in error if inaccessible

State-Changed-From-To: closed-open
State-Changed-By: coar
State-Changed-When: Tue Sep 29 07:52:09 PDT 1998

No, it is not fixed.  To reproduce the problem, create
an "index.html" file in a directory, ensure that the server
can't access it, and also make sure that the DirectoryIndex
directive includes "index.html".  Then try to access
"mumble/" for that directory.  The error *should* say
"Forbidden .. mumble/" but instead it says "Forbidden ..
mumble/index.html" -- thus exposing information not
present in the original request.

View raw message