Skip to content

HTTPS clone URL

Subversion checkout URL

You can clone with HTTPS or Subversion.

Download ZIP
Browse files

BUGFIX Disallow web access to cms/silverstripe_version to avoid infor…

…mation leakage (from r114770)

git-svn-id: svn://svn.silverstripe.com/silverstripe/open/modules/cms/branches/2.4@114771 467b73ca-7a2a-4603-9d3b-597d59a354a9
  • Loading branch information...
commit 357b868b4f78247160a49f015341fcb7fe2cef4d 1 parent 375151c
Ingo Schommer chillu authored sminnee committed
Showing with 14 additions and 0 deletions.
  1. +3 −0  .htaccess
  2. +11 −0 web.config
3  .htaccess
View
@@ -1,3 +1,6 @@
<FilesMatch "\.(php|php3|php4|php5|phtml|inc)$">
Deny from all
+</FilesMatch>
+<FilesMatch "silverstripe_version$">
+ Deny from all
</FilesMatch>
11 web.config
View
@@ -0,0 +1,11 @@
+<configuration>
+ <system.webServer>
+ <security>
+ <requestFiltering>
+ <hiddenSegments>
+ <add segment="silverstripe_version" />
+ </hiddenSegments>
+ </requestFiltering>
+ </security>
+ </system.webServer>
+</configuration>
Please sign in to comment.
Something went wrong with that request. Please try again.