Re: redirect vulnerability after upgrading to Struts 2.3.16.2

2014-07-16 Thread Lukasz Lenart
This vulnerability was resolved in 2.3.15.1, more details here http://struts.apache.org/release/2.3.x/docs/s2-017.html For sure you must switch off devMode in production, thus has large impact on overall application performance 2014-07-16 17:28 GMT+02:00 saikrishna : > Hi Getting the below error.

Please need help how to color the chosen elements

2014-07-16 Thread Amine BADID
Hi All. I want to know how to color the chosen elements in a drop-down list ? Thank you in advance. Amine

Re: Upgrading from Struts 2.0 to 2.3.16

2014-07-16 Thread Ken McWilliams
I'd be of the mind that during the upgrade that some how the resource: '/mmr/jsp/templates/layout_ admin_window.jsp' and other folders were somehow moved and that "org.apache.tiles. TilesException: ServletException including path" is perfectly accurate. Generally you don't want templates to be expo

redirect vulnerability after upgrading to Struts 2.3.16.2

2014-07-16 Thread saikrishna
Hi Getting the below error.Looks like,somebody tried to attack our application with a redirect.Below is the log.Please advice. ParametersInterceptor:34 - Developer Notification (set struts.devMode to false to disable this message): Unexpected Exception caught setting 'redirect:${#res=#context.g