Security Advisories (1)
CPANSA-Jifty-2011-01 (2011-03-17)

The path as passed in the fragment request data structure was used verbatim in the dispatcher and other locations. This possibly allowed requests to walk around ACLs by requesting '/some/safe/place/../../../dangerous' as a fragment.

NAME

Jifty::Plugin::SkeletonApp::Dispatcher - Dispatcher for SkeletonApp plugin

DESCRIPTION

Elementary things for a basic app.

RULES

on '**'

Add 'Home' item to the top navigation unless it's there already.

before '**'

Sets language of the current session if the request has '_jifty_lang' argument.