assume somebody configures the app, but forgets to 'enable' the default .htaccess. all the configuration then is readable by any user in the web. to prevent this there should be a .htaccess that yields a forbidden in each directory vmsa provides.
Log in to post a comment.