Security Advisories (1)
CVE-2017-16248 (2017-10-31)

The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there is a '.' character anywhere in the pathname, which differs from the intended policy of allowing access only when the filename itself has a '.' character.

Changes for version 0.09 - 2005-10-07

  • Added new configuration options to improve security: ignore_extensions - keep certain extensions from being static
    • This option defaults to tt, html, and xhtml to prevent template files from being accessible. ignore_dirs - keep certain dirs from being static
  • include_path is no longer experimental.
  • Added support for hiding log output, depends on Cat 5.50. (Marcus Ramberg)

Modules

Make serving static pages painless.