Actions
Bug #22513
closedChangelog, README, NEWS files should be blocked via htaccess
Status:
Closed
Priority:
Should have
Assignee:
-
Category:
-
Target version:
-
Start date:
2010-04-26
Due date:
% Done:
0%
Estimated time:
TYPO3 Version:
4.4
PHP Version:
5.2
Tags:
Complexity:
Is Regression:
Sprint Focus:
Description
OTRS Ticket ID: 2010042610000013
Files like Changelog, README, NEWS.txt etc. that are publicly visible
allow easy scanning for vulnerable TYPO3 or extension versions.
So TYPO3's default .htaccess should deny access to these files by default.
(issue imported from #M14203)
Actions