Marc Delisle
|
c96500ff1d
|
3.3.10.5 release
|
2011-11-10 08:43:40 -05:00 |
|
Marc Delisle
|
4bd5476eed
|
Merge branch 'MAINT_3_3_10' into QA_3_3
|
2011-11-10 08:36:26 -05:00 |
|
Marc Delisle
|
75606e5f82
|
New PHP requirements for XML and ODS importing
|
2011-11-10 05:26:40 -05:00 |
|
Marc Delisle
|
1a89c8ecfd
|
ChangeLog for 3.3.10.5
|
2011-11-10 05:18:14 -05:00 |
|
Michal Čihař
|
2fbf631384
|
Disable XML loading plugins on old PHP
When libxml_disable_entity_loader is not available, we can not guarantee
safe handling of XML data.
|
2011-11-10 05:14:04 -05:00 |
|
Michal Čihař
|
5fa86b8e81
|
Disable loading of external XML entities when loading XML
Fixes CVE-2011-4107
|
2011-11-10 05:13:35 -05:00 |
|
Marc Delisle
|
e3d3ef7af2
|
Fix merge conflicts
|
2011-11-10 05:07:54 -05:00 |
|
Marc Delisle
|
bd92c092cd
|
3.3.10.4 release
|
2011-08-24 12:16:07 -04:00 |
|
Marc Delisle
|
a60420aa50
|
ChangeLog for 3.3.10.4
|
2011-08-24 12:13:37 -04:00 |
|
Marc Delisle
|
be8cb6c27f
|
Merge branch 'MAINT_3_3_10' into QA_3_3
|
2011-08-24 12:12:47 -04:00 |
|
Marc Delisle
|
6aefed1fbc
|
ChangeLog for 3.3.10.4
|
2011-08-24 12:12:31 -04:00 |
|
Marc Delisle
|
555e0db0ac
|
Merge branch 'MAINT_3_3_10' into QA_3_3
|
2011-08-24 12:10:12 -04:00 |
|
Herman van Rink
|
c79375598d
|
Missing sanitization on the table, column and index names leads to XSS vulnerabilities, see PMASA-2011-13
|
2011-08-19 11:51:21 +02:00 |
|
Herman van Rink
|
a5716cb389
|
Slightly far fetched XSS prevention
|
2011-08-19 11:02:22 +02:00 |
|
Marc Delisle
|
ae20845e36
|
Sanitize filenames before using in Content-Disposition header
|
2011-08-18 19:18:38 +02:00 |
|
Herman van Rink
|
e11e55cb06
|
Make better use of PMA_generate_common_url to prevent XSS
|
2011-08-08 17:31:35 +02:00 |
|
Herman van Rink
|
9d54e57fc8
|
XSS fixes
|
2011-08-08 17:15:48 +02:00 |
|
Herman van Rink
|
c78da15827
|
XSS fixes
|
2011-08-08 17:03:15 +02:00 |
|
Herman van Rink
|
a6c8a8fe8a
|
XSS fixes
|
2011-08-08 16:58:08 +02:00 |
|
Marc Delisle
|
3e95b08ced
|
3.3.10.3 release
|
2011-07-23 08:03:58 -04:00 |
|
Marc Delisle
|
8a5c5c8ef5
|
Fix merge conflicts
|
2011-07-23 07:56:45 -04:00 |
|
Marc Delisle
|
6cb0ad8a0d
|
3.3.10.3 release date
|
2011-07-23 07:54:38 -04:00 |
|
Herman van Rink
|
2254a70fad
|
Updated/fixed Changelog
|
2011-07-22 20:15:08 +02:00 |
|
Herman van Rink
|
8ac8328229
|
Backported fix for PMASA-2011-9 to 3.3
|
2011-07-22 20:14:50 +02:00 |
|
Michal Čihař
|
630b8260be
|
Pass token along with swekey auth requests
|
2011-07-12 13:07:08 +02:00 |
|
Herman van Rink
|
f6f6ee3f11
|
[security] Fixed possible session manipulation in swekey authentication, see PMASA-2011-12
|
2011-07-12 13:07:01 +02:00 |
|
Marc Delisle
|
1d60fb6da9
|
3.3.10.2 release
|
2011-07-02 20:45:06 -04:00 |
|
Marc Delisle
|
b8be5ebe2f
|
Merge branch 'MAINT_3_3_10' into QA_3_3
|
2011-07-02 20:42:04 -04:00 |
|
Marc Delisle
|
ab31a2565f
|
3.3.10.2 release
|
2011-07-02 20:39:57 -04:00 |
|
Herman van Rink
|
5ee357a572
|
Fixed filtering of a file path, which allowed for directory traversal, see PMASA-2011-8
|
2011-06-30 20:19:32 +02:00 |
|
Herman van Rink
|
911a83393e
|
Updated Changelog to add PMASA references
|
2011-06-30 12:34:16 +02:00 |
|
Herman van Rink
|
ca74f480f1
|
Fixed regexp quoting issue in Synchronize code
|
2011-06-30 09:59:43 +02:00 |
|
Herman van Rink
|
2e01647949
|
Fixed possible code injection incase session variables are compromised
|
2011-06-29 13:02:00 +02:00 |
|
Herman van Rink
|
6e6e129f26
|
Fixed possible session corruption in swekey authentication
|
2011-06-29 08:51:44 +02:00 |
|
Marc Delisle
|
6eae88e65f
|
3.3.10.1
|
2011-05-20 13:02:23 -04:00 |
|
Marc Delisle
|
1ec75facaf
|
Fix merge conflict
|
2011-05-20 12:29:07 -04:00 |
|
Marc Delisle
|
0c2a2a6220
|
XSS on Tracking page
|
2011-05-20 12:27:55 -04:00 |
|
Herman van Rink
|
1300510d36
|
XSS in Tracking page, more
|
2011-05-19 22:39:43 +02:00 |
|
Herman van Rink
|
452669a174
|
XSS in Tracking page
|
2011-05-19 22:16:52 +02:00 |
|
Herman van Rink
|
7ebe311433
|
Add missing PMA_sqlAddslashes to $initial parameter
Security risk is low since a valid token is required to use this.
|
2011-04-26 16:28:50 +02:00 |
|
Herman van Rink
|
2928a557a7
|
Translation update for dutch
|
2011-04-15 21:17:20 +02:00 |
|
Michal Čihař
|
788fadfccf
|
Resort language files
|
2011-03-24 15:56:07 +01:00 |
|
Michal Čihař
|
80fe2be243
|
Backport translations from master in case there will ever be new 3.3 release
|
2011-03-24 15:53:05 +01:00 |
|
Marc Delisle
|
86cdc9f7bb
|
3.3.11-dev
|
2011-03-19 07:58:11 -04:00 |
|
Marc Delisle
|
bec6e74bd3
|
Merge remote branch 'origin/MAINT_3_3_10' into QA_3_3
|
2011-03-19 07:55:55 -04:00 |
|
Marc Delisle
|
3e31ab1172
|
3.3.10
|
2011-03-19 07:54:50 -04:00 |
|
Marc Delisle
|
0527c3ea78
|
3.3.11-dev
|
2011-03-12 13:33:43 -05:00 |
|
Marc Delisle
|
a80d0892f8
|
3.3.10-rc1
|
2011-03-12 13:30:22 -05:00 |
|
Michal Čihař
|
e71bd6ae1a
|
Resort
|
2011-02-21 13:47:32 +01:00 |
|
Michal Čihař
|
c722cf64a3
|
Update German translation, tracker #3187551
|
2011-02-21 13:46:01 +01:00 |
|