www-apache-bugdb mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Dmitry Novikov <dnovi...@tiis.com>
Subject mod_jserv/5610: Incorrect translation of URL information
Date Thu, 20 Jan 2000 17:26:44 GMT

>Number:         5610
>Category:       mod_jserv
>Synopsis:       Incorrect translation of URL information
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    jserv
>State:          open
>Class:          sw-bug
>Submitter-Id:   apache
>Arrival-Date:   Thu Jan 20 09:30:00 PST 2000
>Closed-Date:
>Last-Modified:
>Originator:     dnovikov@tiis.com
>Release:        Apache/1.3.9
>Organization:
apache
>Environment:
Debian (slink, kernel 2.2.10)
Apache/1.3.9 (Unix) Debian/GNU mod_ssl/2.4.10 OpenSSL/0.9.4 ApacheJServ/1.1 
also confirmed on:
Apache/1.3.9 (Unix) secured_by_Raven/1.4.2.4-dev ApacheJServ/1.0
>Description:
Incorrect translation of URL information into SCRIPT_NAME environment variable.
As result of execution http://<hostname>/bin/<servletname>/path/info/anystringwith<servletname>
we will have org.apache.jserv.SCRIPT_NAME = /bin instead of
org.apache.jserv.SCRIPT_NAME = /bin/EnvDumpServlet 
I've not checked with "servlets" instead of "bin", probably result will be the same.
>How-To-Repeat:
<hostname>/servlets/EnvDumpServlet/path/info/anystringwithEnvDumpServlet
>Fix:

>Release-Note:
>Audit-Trail:
>Unformatted:
 [In order for any reply to be added to the PR database, you need]
 [to include <apbugs@Apache.Org> in the Cc line and make sure the]
 [subject line starts with the report component and number, with ]
 [or without any 'Re:' prefixes (such as "general/1098:" or      ]
 ["Re: general/1098:").  If the subject doesn't match this       ]
 [pattern, your message will be misfiled and ignored.  The       ]
 ["apbugs" address is not added to the Cc line of messages from  ]
 [the database automatically because of the potential for mail   ]
 [loops.  If you do not include this Cc, your reply may be ig-   ]
 [nored unless you are responding to an explicit request from a  ]
 [developer.  Reply only with text; DO NOT SEND ATTACHMENTS!     ]
 
 


Mime
View raw message