Skip to content

Commit

Permalink
Fix #12607: Update installation instructions regarding admin directory
Browse files Browse the repository at this point in the history
The /admin/ directory should be removed after installation or upgrading
of MantisBT. The installation instructions did not state this
requirement and therefore it was quite easy for users to leave this
potentially dangerous directory in place on live installations of
MantisBT connected to the Internet.
  • Loading branch information
davidhicks committed Dec 15, 2010
1 parent 974e6da commit 065c99c
Showing 1 changed file with 8 additions and 1 deletion.
9 changes: 8 additions & 1 deletion doc/INSTALL
Expand Up @@ -31,6 +31,10 @@ INSTALLATION
* Installation is complete -- you may need to copy the default configuration
to mantisbt/config_inc.php if your web server does not have write access

* Remove the admin/ directory from within the MantisBT installation path. The
scripts within this directory should not be accessible on a live MantisBT
site or on any installation that is accessible via the Internet.

UPGRADING

* Backup your existing installation and database -- really!
Expand All @@ -50,5 +54,8 @@ UPGRADING

* Click install/upgrade

* Upgrading is complete
* Remove the admin/ directory from within the MantisBT installation path. The
scripts within this directory should not be accessible on a live MantisBT
site or on any installation that is accessible via the Internet.

* Upgrading is complete

0 comments on commit 065c99c

Please sign in to comment.