Comment 29 for bug 690482

Revision history for this message
In , Jan (jan-redhat-bugs) wrote :

Gianluca, David, thank you for the comments:
https://bugzilla.redhat.com/show_bug.cgi?id=663230#c5
https://bugzilla.redhat.com/show_bug.cgi?id=663230#c6

(In reply to comment #5)
> I guess it's relevant to note the default apache configuration provided with
> the mantis package includes the following.
>
>
> # Admin directory access is disabled by default; do not change this unless
> # you are performing the first installation or a database schema update.
> # See README.Fedora for more details

Based on the above comments decreased severity of the issues
to moderate. But we should still address them (to sanitize /
protect also not so likely configurations).