Date: Wed, 22 May 2002 01:07:23 -0700 (PDT) From: Akinori MUSHA <knu@FreeBSD.org> To: cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org Subject: cvs commit: projects/cvsweb ChangeLog cvsweb.cgi Message-ID: <200205220807.g4M87NU67507@freefall.freebsd.org>
index | next in thread | raw e-mail
knu 2002/05/22 01:07:23 PDT
Modified files:
cvsweb ChangeLog cvsweb.cgi
Log:
* cvsweb.cgi: Previous fixes against cross-site scripting
vulnerabilities were insufficient and buggy (error messages were
messed up). Revamp fatal() to HTML-quote automatically and fix
error message output.
Revision Changes Path
1.39 +5 -0 projects/cvsweb/ChangeLog
1.103 +88 -77 projects/cvsweb/cvsweb.cgi
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe cvs-all" in the body of the message
home |
help
Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200205220807.g4M87NU67507>
