Bug Report: Security: Can view /components/com_fabrik directory.

tek

Member
This is only possible if the server configuration for apache has <Directory /Path/2/WEBROOT Options Indexes
enabled. If it is all of your exports will be viewable for everyone with that configuration.

It's also easily resolved by just dropping a index.html file into the /components/com_fabrik folder. This could be really bad though cause if you have attempted any exports they get stored here and are now viewable by everyone. Simple fix but very required.

Some servers might look for a index.htm file before the index.html file so in the interest of security you could create the file with that name instead but for packaging as a minimum the index.html file should be added.
 
We are in need of some funding.
More details.

Thank you.

Members online

Back
Top