BUGFIX Disallow web access to cms/silverstripe_version to avoid information leakage

git-svn-id: svn://svn.silverstripe.com/silverstripe/open/modules/cms/trunk@114770 467b73ca-7a2a-4603-9d3b-597d59a354a9
This commit is contained in:
Ingo Schommer 2010-12-09 22:50:52 +00:00
parent a11b1dd285
commit f298fc2a2d
2 changed files with 14 additions and 0 deletions

View File

@ -1,3 +1,6 @@
<FilesMatch "\.(php|php3|php4|php5|phtml|inc)$"> <FilesMatch "\.(php|php3|php4|php5|phtml|inc)$">
Deny from all Deny from all
</FilesMatch> </FilesMatch>
<FilesMatch "silverstripe_version$">
Deny from all
</FilesMatch>

11
web.config Normal file
View File

@ -0,0 +1,11 @@
<configuration>
<system.webServer>
<security>
<requestFiltering>
<hiddenSegments>
<add segment="silverstripe_version" />
</hiddenSegments>
</requestFiltering>
</security>
</system.webServer>
</configuration>