Commit Graph

11574 Commits

Author SHA1 Message Date
Michal Čihař
e6f5e92a27 Merge branch 'QA_3_2' into QA_3_3 2012-04-11 11:07:36 +02:00
Michal Čihař
be3108b3e0 Merge branch 'QA_3_1' into QA_3_2 2012-04-11 11:07:21 +02:00
Michal Čihař
753e52660f Merge branch 'QA_3_0' into QA_3_1 2012-04-11 11:07:11 +02:00
Michal Čihař
8a7cf503a3 Merge branch 'QA_2_11' into QA_3_0 2012-04-11 11:06:59 +02:00
Michal Čihař
fa27f371f4 Merge branch 'QA_2_10' into QA_2_11 2012-04-11 11:06:45 +02:00
Michal Čihař
b09cad4342 Merge branch 'QA_2_9' into QA_2_10 2012-04-11 11:06:39 +02:00
Michal Čihař
a6c4ea2f7e Merge remote-tracking branches 'origin/MAINT_3_3_0', 'origin/MAINT_3_3_1', 'origin/MAINT_3_3_10', 'origin/MAINT_3_3_2', 'origin/MAINT_3_3_3', 'origin/MAINT_3_3_4', 'origin/MAINT_3_3_5', 'origin/MAINT_3_3_6', 'origin/MAINT_3_3_7', 'origin/MAINT_3_3_8' and 'origin/MAINT_3_3_9' into QA_3_3 2012-04-11 11:05:47 +02:00
Michal Čihař
a1ff927fbf Merge remote-tracking branches 'origin/MAINT_3_2_0', 'origin/MAINT_3_2_2', 'origin/MAINT_3_2_3', 'origin/MAINT_3_2_4' and 'origin/MAINT_3_2_5' into QA_3_2 2012-04-11 11:05:46 +02:00
Michal Čihař
1ff6ab9f9a Merge remote-tracking branches 'origin/MAINT_3_1_0', 'origin/MAINT_3_1_1', 'origin/MAINT_3_1_2', 'origin/MAINT_3_1_3', 'origin/MAINT_3_1_4' and 'origin/MAINT_3_1_5' into QA_3_1 2012-04-11 11:05:46 +02:00
Michal Čihař
d972e71e0a Merge remote-tracking branches 'origin/MAINT_3_0_0' and 'origin/MAINT_3_0_1' into QA_3_0 2012-04-11 11:05:45 +02:00
Michal Čihař
62306d3e6a Merge remote-tracking branches 'origin/MAINT_2_9_0', 'origin/MAINT_2_9_1' and 'origin/MAINT_2_9_2' into QA_2_9 2012-04-11 11:05:45 +02:00
Michal Čihař
828d01d203 Merge remote-tracking branches 'origin/MAINT_2_11_0', 'origin/MAINT_2_11_1', 'origin/MAINT_2_11_10', 'origin/MAINT_2_11_11', 'origin/MAINT_2_11_2', 'origin/MAINT_2_11_3', 'origin/MAINT_2_11_4', 'origin/MAINT_2_11_5', 'origin/MAINT_2_11_6', 'origin/MAINT_2_11_7', 'origin/MAINT_2_11_8' and 'origin/MAINT_2_11_9' into QA_2_11 2012-04-11 11:05:44 +02:00
Michal Čihař
977ec6f8e2 Merge remote-tracking branches 'origin/MAINT_2_10_0', 'origin/MAINT_2_10_2' and 'origin/MAINT_2_10_3' into QA_2_10 2012-04-11 11:05:43 +02:00
Marc Delisle
c96500ff1d 3.3.10.5 release 2011-11-10 08:43:40 -05:00
Marc Delisle
6f982a1645 3.3.10.5 release 2011-11-10 08:42:22 -05:00
Marc Delisle
4bd5476eed Merge branch 'MAINT_3_3_10' into QA_3_3 2011-11-10 08:36:26 -05:00
Marc Delisle
75606e5f82 New PHP requirements for XML and ODS importing 2011-11-10 05:26:40 -05:00
Marc Delisle
1a89c8ecfd ChangeLog for 3.3.10.5 2011-11-10 05:18:14 -05:00
Michal Čihař
2fbf631384 Disable XML loading plugins on old PHP
When libxml_disable_entity_loader is not available, we can not guarantee
safe handling of XML data.
2011-11-10 05:14:04 -05:00
Michal Čihař
5fa86b8e81 Disable loading of external XML entities when loading XML
Fixes CVE-2011-4107
2011-11-10 05:13:35 -05:00
Marc Delisle
e3d3ef7af2 Fix merge conflicts 2011-11-10 05:07:54 -05:00
Marc Delisle
bd92c092cd 3.3.10.4 release 2011-08-24 12:16:07 -04:00
Marc Delisle
a60420aa50 ChangeLog for 3.3.10.4 2011-08-24 12:13:37 -04:00
Marc Delisle
be8cb6c27f Merge branch 'MAINT_3_3_10' into QA_3_3 2011-08-24 12:12:47 -04:00
Marc Delisle
6aefed1fbc ChangeLog for 3.3.10.4 2011-08-24 12:12:31 -04:00
Marc Delisle
555e0db0ac Merge branch 'MAINT_3_3_10' into QA_3_3 2011-08-24 12:10:12 -04:00
Herman van Rink
c79375598d Missing sanitization on the table, column and index names leads to XSS vulnerabilities, see PMASA-2011-13 2011-08-19 11:51:21 +02:00
Herman van Rink
a5716cb389 Slightly far fetched XSS prevention 2011-08-19 11:02:22 +02:00
Marc Delisle
ae20845e36 Sanitize filenames before using in Content-Disposition header 2011-08-18 19:18:38 +02:00
Herman van Rink
e11e55cb06 Make better use of PMA_generate_common_url to prevent XSS 2011-08-08 17:31:35 +02:00
Herman van Rink
9d54e57fc8 XSS fixes 2011-08-08 17:15:48 +02:00
Herman van Rink
c78da15827 XSS fixes 2011-08-08 17:03:15 +02:00
Herman van Rink
a6c8a8fe8a XSS fixes 2011-08-08 16:58:08 +02:00
Marc Delisle
3e95b08ced 3.3.10.3 release 2011-07-23 08:03:58 -04:00
Marc Delisle
8a5c5c8ef5 Fix merge conflicts 2011-07-23 07:56:45 -04:00
Marc Delisle
6cb0ad8a0d 3.3.10.3 release date 2011-07-23 07:54:38 -04:00
Herman van Rink
2254a70fad Updated/fixed Changelog 2011-07-22 20:15:08 +02:00
Herman van Rink
8ac8328229 Backported fix for PMASA-2011-9 to 3.3 2011-07-22 20:14:50 +02:00
Michal Čihař
630b8260be Pass token along with swekey auth requests 2011-07-12 13:07:08 +02:00
Herman van Rink
f6f6ee3f11 [security] Fixed possible session manipulation in swekey authentication, see PMASA-2011-12 2011-07-12 13:07:01 +02:00
Marc Delisle
1d60fb6da9 3.3.10.2 release 2011-07-02 20:45:06 -04:00
Marc Delisle
b8be5ebe2f Merge branch 'MAINT_3_3_10' into QA_3_3 2011-07-02 20:42:04 -04:00
Marc Delisle
ab31a2565f 3.3.10.2 release 2011-07-02 20:39:57 -04:00
Herman van Rink
5ee357a572 Fixed filtering of a file path, which allowed for directory traversal, see PMASA-2011-8 2011-06-30 20:19:32 +02:00
Herman van Rink
911a83393e Updated Changelog to add PMASA references 2011-06-30 12:34:16 +02:00
Herman van Rink
ca74f480f1 Fixed regexp quoting issue in Synchronize code 2011-06-30 09:59:43 +02:00
Herman van Rink
2e01647949 Fixed possible code injection incase session variables are compromised 2011-06-29 13:02:00 +02:00
Herman van Rink
6e6e129f26 Fixed possible session corruption in swekey authentication 2011-06-29 08:51:44 +02:00
Marc Delisle
6eae88e65f 3.3.10.1 2011-05-20 13:02:23 -04:00
Marc Delisle
1ec75facaf Fix merge conflict 2011-05-20 12:29:07 -04:00