Path to this page:
Subject: CVS commit: pkgsrc/devel/mantis
From: Adrian Portelli
Date: 2006-05-01 15:00:40
Message id: 20060501130040.587CF2DA27@cvs.netbsd.org
Log Message:
Update to 1.0.2
> 2006.04.18 - 1.0.2
> - 0006902: [security] XSS in mantis bug track system .... (thraxisp)
> - 0006859: [bugtracker] Can send reminders to all recipients (thraxisp)
>
> 2006.02.18 - 1.0.1
> - 0006722: [installation] Remaining mysqli_ install problems (ref. \
#0006672): my sqli_real_escape_string() expects parameter 1 to be link \
(thraxisp)
> - 0006672: [installation] install.php assumes mysql extension, fails with \
mysqli extension (thraxisp)
> - 0006668: [filters] Parse error while saving new filter: Call to undefined \
function: string_strip_tags() (thraxisp)
>
> 2006.02.04 - 1.0.0
> - 0006044: [security] 'Return' _GET is not checked (thraxisp)
> - 0006650: [security] ADOdb can be exploited to execute arbitrary SQL code \
(vboctor)
> - 0006659: [security] Cross site scripting vulnerability (thraxisp)
> - 0006634: [filters] Filter does not work with profiles (vboctor)
Files: