Security Advisories (4)
CPANSA-Jifty-2011-01 (2011-03-17)

The path as passed in the fragment request data structure was used verbatim in the dispatcher and other locations. This possibly allowed requests to walk around ACLs by requesting '/some/safe/place/../../../dangerous' as a fragment.

CPANSA-Jifty-2009-01 (2009-04-09)

The REST plugin would let you call any method on the model.

CPANSA-Jifty-2008-01 (2009-04-08)

Allowed all actions on GET.

CPANSA-Jifty-2006-01 (2006-07-06)

Jifty did not protect users against a class of remote data access vulnerability. If an attacker knew the structure of your local filesystem and you were using the "standalone" webserver in production, the attacker could gain read only access to local files.

NAME

Jifty::Script::Server - A standalone webserver for your Jifty application

DESCRIPTION

When you're getting started with Jifty, this is the server you want. It's lightweight and easy to work with.

API

options

The server takes only one option, --port, the port to run the server on. This is overrides the port in the config file, if it is set there. The default port is 8888.

run

run takes no arguments, but starts up a Jifty server process for you.