Security Advisories (1)
CVE-2017-16248 (2017-10-31)

The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there is a '.' character anywhere in the pathname, which differs from the intended policy of allowing access only when the filename itself has a '.' character.

Changes for version 0.16 - 2007-04-30

  • Allow all files in directories defined by the config option 'dirs' to be served as static even if the file matches ignore_dirs or ignore_extensions.
  • Fixed bug where 204 or 304 status codes would result in a 500 error under mod_perl.
  • Switch to Module::Install.

Modules

Make serving static pages painless.