From owner-cvs-all Wed May 8 8:34:41 2002 Delivered-To: cvs-all@freebsd.org Received: from tao.org.uk (genius.tao.org.uk [212.135.162.51]) by hub.freebsd.org (Postfix) with ESMTP id C947537B405; Wed, 8 May 2002 08:34:32 -0700 (PDT) Received: by tao.org.uk (Postfix, from userid 100) id A6A04117; Wed, 8 May 2002 16:34:14 +0100 (BST) Date: Wed, 8 May 2002 16:34:14 +0100 From: Josef Karthauser To: Motoyuki Konno Cc: cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org Subject: Re: cvs commit: www/en/cgi cvsweb.cgi Message-ID: <20020508153414.GC14613@genius.tao.org.uk> References: <200205080542.g485gQ125543@freefall.freebsd.org> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="96YOpH+ONegL0A3E" Content-Disposition: inline In-Reply-To: <200205080542.g485gQ125543@freefall.freebsd.org> User-Agent: Mutt/1.3.28i Sender: owner-cvs-all@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG --96YOpH+ONegL0A3E Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Tue, May 07, 2002 at 10:42:26PM -0700, Motoyuki Konno wrote: > motoyuki 2002/05/07 22:42:26 PDT >=20 > Modified files: > en/cgi cvsweb.cgi=20 > Log: > Fix cross-site scripting vulnerablity. > =20 > This problem was reported at www.jp.FreeBSD.org, which uses the > (almost) same CGI script as www.FreeBSD.org. Can you commit this to projects/cvsweb/cvsweb.cgi also please? Joe --96YOpH+ONegL0A3E Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (FreeBSD) Comment: For info see http://www.gnupg.org iEYEARECAAYFAjzZRXYACgkQXVIcjOaxUBY0lQCfaTizMqAuIg1q5iDFzmaPcGy/ 1TIAnAsTFIJyeWLdTVSTZjqFxYic05ii =Lj/y -----END PGP SIGNATURE----- --96YOpH+ONegL0A3E-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe cvs-all" in the body of the message