[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-security] Cobalt Cube Webmail directory traversal (fwd)

On Fri, 6 Jul 2001, shimi wrote:


> And in any case I am still correct... if a webserver has a server root, in
> no case the webserver shall send out a page on a directory upper than it's
> server root. That's only my opinion, though... (chroot was made for
> limiting software to the exact same thing)

Apache ships with chroot support - Cobalt don't use it by default.