You can browse into the zen directory

Just discovered that you can browse right into the /zen directory and thus access any of the admin files. I stuck an "index.html" file in that directory with this meta line in it:

<meta http-equiv="refresh" content="0;URL=admin.php">

That works and I feel better. Was there a better way?

Comments

  • koffee Member
    Of course.. You can add some lines to .htacces, i think that it has to do something with open indexes. Or you can place blank index.htm (whatever) to disable this dir.
  • trisweb Administrator
    Maybe we should add that to the release... just for safety's sake. Shouldn't be too big a problem though. Kind of useful to just go to /zen/ for the admin, actually.
  • lokjah Member
    yeah, I second that, it would be best to just go to /zen/ and have the login page.

    hope this shows up in 1.0.3 :)
  • trisweb Administrator
    Done :)
Sign In or Register to comment.