Link [ pkgsrc | NetBSD | pkgsrc git mirror | PR fulltext-search | netbsd commit viewer ]


   
        usage: [branch:branch] [user:user] [path[@revision]] keyword [... [-excludekeyword [...]]] (e.g. branch:MAIN pkgtools/pkg)




switch to index mode

recent branches: MAIN (8h)  pkgsrc-2024Q1 (9d)  pkgsrc-2023Q4 (56d)  pkgsrc-2023Q2 (88d)  pkgsrc-2023Q3 (168d) 

2024-05-27 04:30:44 UTC Now

2008-05-15 10:33:01 UTC pkgsrc-2008Q1 commitmail json YAML

pullup ticket #2380 - requested by adrianp
bugzilla: update for cross-site scripting vulnerability

revisions pulled up:
- pkgsrc/devel/bugzilla/Makefile
- pkgsrc/devel/bugzilla/PLIST
- pkgsrc/devel/bugzilla/distinfo

  Module Name: pkgsrc
  Committed By: adrianp
  Date: Tue May  6 19:36:39 UTC 2008

  Modified Files:
  pkgsrc/devel/bugzilla: Makefile PLIST distinfo

  Log Message:
  2.22.4

  Class:      Cross-Site Scripting
  Versions:    2.17.2 and higher
  Description: When using the "Format for Printing" view of a bug (or
              the "Long Format" of a bug list, which is the same thing),
      there was a cross-site scripting hole--arbitrary text
      from a particular URL parameter could be injected into the
          page without filtering.

(rtr)