FYI - This app seems to have a security hole. Index.java has an action
which accepts a file path and serves a file from the classpath.

I could use this to access .class files etc. Perhaps even your hibernate
cfg file with username password.

Reply via email to