Changesets: MantisBT

master-1.2.x 5858a659

2013-01-23 07:37

dregad


Details Diff
Fix 0015416: XSS issue in adm_config_report.php

If a 'complex' config option contains javascript code, it would be
executed when displaying the page.
Affected Issues
0015416
mod - adm_config_report.php Diff File

master-1.2.x c61dc631

2013-01-23 07:28

dregad


Details Diff
Fix 0015415: XSS vulnerability on Configuration Report page

A project name containing javascript code results in execution of said
code when displaying the filter's project list.

Note that despite using the same function to display the option list,
the vulnerability does not exist for usernames (due to input
restrictions in place when creating/updating user accounts) or config
names (which must exist in config_default_inc.php and must be valid php
identifiers).
Affected Issues
0015415
mod - adm_config_report.php Diff File

master f977b3ca

2013-01-22 20:26

dregad


Details Diff
Fix huge memory consumption for print_user_option_list()

Following the implementation of the fix for 0010130, calling this
function when the current project is ALL_PROJECTS causes a massive surge
in memory usage as the code builds a large array containing the list of
all users in all projects accessible to the current user, and then
reduces it to remove duplicates.

This commit reduces the problem by removing calls to array_merge() and
building the consolidated user list in a single pass, using a while
loop. No-longer-used arrays are unset to free up memory.

Fixes 0015411
Affected Issues
0015411
mod - core/print_api.php Diff File

master-1.2.x e61e63ca

2013-01-22 20:26

dregad


Details Diff
Fix huge memory consumption for print_user_option_list()

Following the implementation of the fix for 0010130, calling this
function when the current project is ALL_PROJECTS causes a massive surge
in memory usage as the code builds a large array containing the list of
all users in all projects accessible to the current user, and then
reduces it to remove duplicates.

This commit reduces the problem by removing calls to array_merge() and
building the consolidated user list in a single pass, using a while
loop. No-longer-used arrays are unset to free up memory.

Fixes 0015411
Affected Issues
0015411
mod - core/print_api.php Diff File

master-1.2.x ced463b1

2013-01-22 20:26

dregad


Details Diff
Changed version to 1.2.14dev
mod - core/constant_inc.php Diff File

master-2.0.x ed227ddd

2013-01-22 19:01

Paul Richards


Details Diff
fix typo
mod - core/user_pref_api.php Diff File

master-2.0.x b55d30ce

2013-01-22 19:00

Paul Richards


Details Diff
Remove reference to old utf8 library
mod - core.php Diff File

master-1.2.x 9147d9d3

2013-01-22 07:43

dregad


Details Diff
Bump version and update release notes for 1.2.14
mod - core/constant_inc.php Diff File
mod - doc/RELEASE Diff File

master-1.2.x d38abf95

2013-01-22 07:43

dregad


Details Diff
Bump version and update release notes for 1.2.13
mod - core/constant_inc.php Diff File
mod - doc/RELEASE Diff File

master-1.2.x e539dd68

2013-01-22 05:10

dregad


Details Diff
Merge branch 'manage-config' into master-1.2.x

This branch implements several improvements to the Manage Configuration
page, including:

- better performance
- filtering
- ability to edit config options
mod - adm_config_report.php Diff File
mod - adm_config_set.php Diff File
mod - config_defaults_inc.php Diff File
mod - core/constant_inc.php Diff File
mod - core/form_api.php Diff File
mod - core/helper_api.php Diff File
mod - core/obsolete.php Diff File
mod - core/print_api.php Diff File
mod - docbook/administration_guide/en/configuration.sgml Diff File
mod - lang/strings_english.txt Diff File
mod - manage_user_page.php Diff File

master-1.2.x 00524351

2013-01-22 01:15

siebrand


Details Diff
Localisation updates from http://translatewiki.net.
mod - lang/strings_dutch.txt Diff File
mod - lang/strings_french.txt Diff File
mod - lang/strings_galician.txt Diff File
mod - lang/strings_german.txt Diff File
mod - lang/strings_korean.txt Diff File
mod - lang/strings_macedonian.txt Diff File
mod - lang/strings_russian.txt Diff File
mod - lang/strings_spanish.txt Diff File
mod - lang/strings_swedish.txt Diff File

master-2.0.x 0695ceb2

2013-01-19 20:41

Paul Richards


Details Diff
remove unused function param
mod - core/authentication_api.php Diff File

master-2.0.x 8f72b641

2013-01-19 20:38

Paul Richards


Details Diff
Update Copyright Statements
mod - account_delete.php Diff File
mod - account_manage_columns_page.php Diff File
mod - account_page.php Diff File
mod - account_prefs_inc.php Diff File
mod - account_prefs_page.php Diff File
mod - account_prefs_reset.php Diff File
mod - account_prefs_update.php Diff File
mod - account_prof_edit_page.php Diff File
mod - account_prof_menu_page.php Diff File
mod - account_prof_update.php Diff File
mod - account_sponsor_page.php Diff File
mod - account_sponsor_update.php Diff File
mod - account_update.php Diff File
mod - admin/check/check_L10n_inc.php Diff File
mod - admin/check/check_anonymous_inc.php Diff File
mod - admin/check/check_api.php Diff File
mod - admin/check/check_attachments_inc.php Diff File
mod - admin/check/check_config_inc.php Diff File
mod - admin/check/check_crypto_inc.php Diff File
mod - admin/check/check_database_inc.php Diff File
mod - admin/check/check_display_inc.php Diff File
mod - admin/check/check_email_inc.php Diff File
mod - admin/check/check_i18n_inc.php Diff File
mod - admin/check/check_integrity_inc.php Diff File
mod - admin/check/check_paths_inc.php Diff File
mod - admin/check/check_php_inc.php Diff File
mod - admin/check/index.php Diff File
mod - admin/db_stats.php Diff File
mod - admin/email_queue.php Diff File
mod - admin/index.php Diff File
mod - admin/install.php Diff File
mod - admin/move_db2disk.php Diff File
mod - admin/system_utils.php Diff File
mod - admin/test_langs.php Diff File
mod - admin/upgrade_warning.php Diff File
mod - billing_inc.php Diff File
mod - billing_page.php Diff File
mod - browser_search_plugin.php Diff File
mod - bug_actiongroup.php Diff File
mod - bug_actiongroup_add_note_inc.php Diff File
mod - bug_actiongroup_attach_tags_inc.php Diff File
mod - bug_actiongroup_ext.php Diff File
mod - bug_actiongroup_ext_page.php Diff File
mod - bug_actiongroup_page.php Diff File
mod - bug_actiongroup_update_product_build_inc.php Diff File
mod - bug_actiongroup_update_severity_inc.php Diff File
mod - bug_change_status_page.php Diff File
mod - bug_file_add.php Diff File
mod - bug_file_delete.php Diff File
mod - bug_file_upload_inc.php Diff File
mod - bug_monitor_add.php Diff File
mod - bug_monitor_delete.php Diff File
mod - bug_monitor_list_view_inc.php Diff File
mod - bug_relationship_add.php Diff File
mod - bug_relationship_delete.php Diff File
mod - bug_relationship_graph.php Diff File
mod - bug_relationship_graph_img.php Diff File
mod - bug_reminder.php Diff File
mod - bug_reminder_page.php Diff File
mod - bug_report.php Diff File
mod - bug_report_page.php Diff File
mod - bug_revision_drop.php Diff File
mod - bug_revision_view_page.php Diff File
mod - bug_set_sponsorship.php Diff File
mod - bug_sponsorship_list_view_inc.php Diff File
mod - bug_stick.php Diff File
mod - bug_update.php Diff File
mod - bug_update_page.php Diff File
mod - bug_view_advanced_page.php Diff File
mod - bug_view_inc.php Diff File
mod - bug_view_page.php Diff File
mod - bugnote_add.php Diff File
mod - bugnote_add_inc.php Diff File
mod - bugnote_delete.php Diff File
mod - bugnote_edit_page.php Diff File
mod - bugnote_set_view_state.php Diff File
mod - bugnote_stats_inc.php Diff File
mod - bugnote_update.php Diff File
mod - bugnote_view_inc.php Diff File
mod - changelog_page.php Diff File
mod - config_defaults_inc.php Diff File
mod - core.php Diff File
mod - core/access_api.php Diff File
mod - core/authentication_api.php Diff File
mod - core/bug_api.php Diff File
mod - core/bug_group_action_api.php Diff File
mod - core/bug_revision_api.php Diff File
mod - core/bugnote_api.php Diff File
mod - core/category_api.php Diff File
mod - core/cfdefs/cfdef_standard.php Diff File
mod - core/classes/Exception/Access/AccessDenied.class.php Diff File
mod - core/classes/Exception/Access/InsufficientAccessLevel.class.php Diff File
mod - core/classes/Exception/Authentication/LostPasswordBlankEmail.class.php Diff File
mod - core/classes/Exception/Authentication/LostPasswordDisabled.class.php Diff File
mod - core/classes/Exception/Column/ColumnDuplicate.class.php Diff File
mod - core/classes/Exception/Column/ColumnInvalid.class.php Diff File
mod - core/classes/Exception/Configuration/OptionCannotBeSetInDatabase.class.php Diff File
mod - core/classes/Exception/Configuration/OptionInvalidValue.class.php Diff File
mod - core/classes/Exception/Configuration/OptionNotFound.class.php Diff File
mod - core/classes/Exception/CustomField/FieldNotFound.class.php Diff File
mod - core/classes/Exception/CustomField/InvalidDefinition.class.php Diff File
mod - core/classes/Exception/CustomField/NameNotUnique.class.php Diff File
mod - core/classes/Exception/CustomField/NotLinkedToProject.class.php Diff File
mod - core/classes/Exception/Database/ConnectionFailed.class.php Diff File
mod - core/classes/Exception/Database/FieldNotFound.class.php Diff File
mod - core/classes/Exception/Database/QueryFailed.class.php Diff File
mod - core/classes/Exception/Email/AddressInvalid.class.php Diff File
mod - core/classes/Exception/Email/DisposableAddressNotAllowed.class.php Diff File
mod - core/classes/Exception/ExceptionAbstract.class.php Diff File
mod - core/classes/Exception/FTP/ConnectionFailed.class.php Diff File
mod - core/classes/Exception/Field/EmptyField.class.php Diff File
mod - core/classes/Exception/Field/InvalidValue.class.php Diff File
mod - core/classes/Exception/File/FileDuplicate.class.php Diff File
mod - core/classes/Exception/File/FileMoveFailed.class.php Diff File
mod - core/classes/Exception/File/FileNoUpload.class.php Diff File
mod - core/classes/Exception/File/FileTooBig.class.php Diff File
mod - core/classes/Exception/File/FileTypeNotAllowed.class.php Diff File
mod - core/classes/Exception/File/FileUploadFailed.class.php Diff File
mod - core/classes/Exception/File/InvalidUploadPath.class.php Diff File
mod - core/classes/Exception/Filter/FilterNotFound.class.php Diff File
mod - core/classes/Exception/Filter/FilterTooOldToUpgrade.class.php Diff File
mod - core/classes/Exception/Issue/Category/CategoryDuplicate.class.php Diff File
mod - core/classes/Exception/Issue/Category/CategoryNotFound.class.php Diff File
mod - core/classes/Exception/Issue/IssueDuplicateSelf.class.php Diff File
mod - core/classes/Exception/Issue/IssueNotFound.class.php Diff File
mod - core/classes/Exception/Issue/IssueReadOnly.class.php Diff File
mod - core/classes/Exception/Issue/Note/NoteNotFound.class.php Diff File
mod - core/classes/Exception/Issue/Relationship/RelationshipDuplicate.class.php Diff File
mod - core/classes/Exception/Issue/Relationship/RelationshipNotFound.class.php Diff File
mod - core/classes/Exception/Issue/Revision/RevisionNotFound.class.php Diff File
mod - core/classes/Exception/Issue/Tag/TagAlreadyAttached.class.php Diff File
mod - core/classes/Exception/Issue/Tag/TagNotAttached.class.php Diff File
mod - core/classes/Exception/Issue/Version/VersionDuplicate.class.php Diff File
mod - core/classes/Exception/Issue/Version/VersionNotFound.class.php Diff File
mod - core/classes/Exception/LDAP/QueryFailed.class.php Diff File
mod - core/classes/Exception/LDAP/ServerConnectFailed.class.php Diff File
mod - core/classes/Exception/Language/LanguageStringNotFound.class.php Diff File
mod - core/classes/Exception/Locale/LocaleNotProvidedByUserAgent.php Diff File
mod - core/classes/Exception/Locale/LocalesNotSupported.php Diff File
mod - core/classes/Exception/News/NewsItemNotFound.class.php Diff File
mod - core/classes/Exception/PHP/ExtensionNotLoaded.class.php Diff File
mod - core/classes/Exception/PHP/HeadersAlreadySent.class.php Diff File
mod - core/classes/Exception/PHP/TimezoneUpdateFailed.class.php Diff File
mod - core/classes/Exception/Plugin/EventNotDeclared.class.php Diff File
mod - core/classes/Exception/Plugin/PluginAlreadyInstalled.class.php Diff File
mod - core/classes/Exception/Plugin/PluginInstallationFailed.class.php Diff File
mod - core/classes/Exception/Plugin/PluginNotRegistered.class.php Diff File
mod - core/classes/Exception/Plugin/PluginPageNotFound.class.php Diff File
mod - core/classes/Exception/Plugin/PluginUpgradeFailed.class.php Diff File
mod - core/classes/Exception/Project/Category/CategoryNotFound.class.php Diff File
mod - core/classes/Exception/Project/ProjectNameNotUnique.class.php Diff File
mod - core/classes/Exception/Project/ProjectNameNotValid.class.php Diff File
mod - core/classes/Exception/Project/ProjectNotFound.class.php Diff File
mod - core/classes/Exception/Project/RecursiveHierarchyNotAllowed.class.php Diff File
mod - core/classes/Exception/Security/CSPRNGNotAvailable.class.php Diff File
mod - core/classes/Exception/Security/CSRFTokenInvalid.class.php Diff File
mod - core/classes/Exception/Security/MasterSaltInvalid.class.php Diff File
mod - core/classes/Exception/Session/SessionHandlerInvalid.class.php Diff File
mod - core/classes/Exception/Session/SessionInvalid.class.php Diff File
mod - core/classes/Exception/Session/SessionVariableNotFound.class.php Diff File
mod - core/classes/Exception/Sponsorship/SponsorshipAmountTooLow.class.php Diff File
mod - core/classes/Exception/Sponsorship/SponsorshipDisabled.class.php Diff File
mod - core/classes/Exception/Sponsorship/SponsorshipNotFound.class.php Diff File
mod - core/classes/Exception/Tag/TagDuplicate.class.php Diff File
mod - core/classes/Exception/Tag/TagNameNotValid.class.php Diff File
mod - core/classes/Exception/Tag/TagNotFound.class.php Diff File
mod - core/classes/Exception/Token/TokenNotFound.class.php Diff File
mod - core/classes/Exception/UnknownException.class.php Diff File
mod - core/classes/Exception/User/PasswordMismatch.class.php Diff File
mod - core/classes/Exception/User/ProtectedLastAdministrator.class.php Diff File
mod - core/classes/Exception/User/ProtectedUser.class.php Diff File
mod - core/classes/Exception/User/UserNameNotUnique.class.php Diff File
mod - core/classes/Exception/User/UserPreferencesNotFound.class.php Diff File
mod - core/classes/Exception/User/UserProfileNotFound.class.php Diff File
mod - core/classes/Exception/Validation/ArrayExpected.class.php Diff File
mod - core/classes/Exception/Validation/ArrayNotExpected.class.php Diff File
mod - core/classes/Exception/Validation/DateFormatInvalid.class.php Diff File
mod - core/classes/Exception/Validation/GPCNotFound.class.php Diff File
mod - core/classes/Exception/Validation/NumberExpected.class.php Diff File
mod - core/classes/MantisBug.class.php Diff File
mod - core/classes/MantisBugRelationshipData.class.php Diff File
mod - core/classes/MantisColumn.class.php Diff File
mod - core/classes/MantisCorePlugin.class.php Diff File
mod - core/classes/MantisCoreWikiPlugin.class.php Diff File
mod - core/classes/MantisDatabase/MantisDatabase.class.php Diff File
mod - core/classes/MantisDatabase/PDO/Mysql/Mysql.class.php Diff File
mod - core/classes/MantisDatabase/PDO/PDO.class.php Diff File
mod - core/classes/MantisDatabaseDict/MantisDatabaseDict.class.php Diff File
mod - core/classes/MantisDatabaseException.class.php Diff File
mod - core/classes/MantisEnum.class.php Diff File
mod - core/classes/MantisError.class.php Diff File
mod - core/classes/MantisException.class.php Diff File
mod - core/classes/MantisFilter.class.php Diff File
mod - core/classes/MantisFormattingPlugin.class.php Diff File
mod - core/classes/MantisLanguage.class.php Diff File
mod - core/classes/MantisPlugin.class.php Diff File
mod - core/classes/MantisUser.class.php Diff File
mod - core/classes/MantisWikiPlugin.class.php Diff File
mod - core/collapse_api.php Diff File
mod - core/columns_api.php Diff File
mod - core/compress_api.php Diff File
mod - core/config_api.php Diff File
mod - core/crypto_api.php Diff File
mod - core/current_user_api.php Diff File
mod - core/custom_field_api.php Diff File
mod - core/custom_function_api.php Diff File
mod - core/database_api.php Diff File
mod - core/date_api.php Diff File
mod - core/email_api.php Diff File
mod - core/email_queue_api.php Diff File
mod - core/event_api.php Diff File
mod - core/events_inc.php Diff File
mod - core/export_api.php Diff File
mod - core/file_api.php Diff File
mod - core/filter_api.php Diff File
mod - core/filter_constants_inc.php Diff File
mod - core/form_api.php Diff File
mod - core/gpc_api.php Diff File
mod - core/graphviz_api.php Diff File
mod - core/helper_api.php Diff File
mod - core/history_api.php Diff File
mod - core/html_api.php Diff File
mod - core/http_api.php Diff File
mod - core/icon_api.php Diff File
mod - core/install_helper_functions_api.php Diff File
mod - core/lang_api.php Diff File
mod - core/last_visited_api.php Diff File
mod - core/ldap_api.php Diff File
mod - core/logging_api.php Diff File
mod - core/news_api.php Diff File
mod - core/obsolete.php Diff File
mod - core/php_api.php Diff File
mod - core/plugin_api.php Diff File
mod - core/prepare_api.php Diff File
mod - core/print_api.php Diff File
mod - core/profile_api.php Diff File
mod - core/project_api.php Diff File
mod - core/project_hierarchy_api.php Diff File
mod - core/relationship_api.php Diff File
mod - core/relationship_graph_api.php Diff File
mod - core/rss_api.php Diff File
mod - core/session_api.php Diff File
mod - core/sponsorship_api.php Diff File
mod - core/string_api.php Diff File
mod - core/summary_api.php Diff File
mod - core/tag_api.php Diff File
mod - core/tokens_api.php Diff File
mod - core/twitter_api.php Diff File
mod - core/user_api.php Diff File
mod - core/user_pref_api.php Diff File
mod - core/utility_api.php Diff File
mod - core/version_api.php Diff File
mod - core/wiki_api.php Diff File
mod - core/workflow_api.php Diff File
mod - core/xmlhttprequest_api.php Diff File
mod - export.php Diff File
mod - file_download.php Diff File
mod - history_inc.php Diff File
mod - img_ext.php Diff File
mod - index.php Diff File
mod - issues_rss.php Diff File
mod - javascript_config.php Diff File
mod - javascript_translations.php Diff File
mod - lang/strings_afrikaans.txt Diff File
mod - lang/strings_amharic.txt Diff File
mod - lang/strings_arabic.txt Diff File
mod - lang/strings_arabicegyptianspoken.txt Diff File
mod - lang/strings_breton.txt Diff File
mod - lang/strings_bulgarian.txt Diff File
mod - lang/strings_catalan.txt Diff File
mod - lang/strings_chinese_simplified.txt Diff File
mod - lang/strings_chinese_traditional.txt Diff File
mod - lang/strings_croatian.txt Diff File
mod - lang/strings_czech.txt Diff File
mod - lang/strings_danish.txt Diff File
mod - lang/strings_dutch.txt Diff File
mod - lang/strings_english.txt Diff File
mod - lang/strings_estonian.txt Diff File
mod - lang/strings_finnish.txt Diff File
mod - lang/strings_french.txt Diff File
mod - lang/strings_galician.txt Diff File
mod - lang/strings_german.txt Diff File
mod - lang/strings_greek.txt Diff File
mod - lang/strings_hebrew.txt Diff File
mod - lang/strings_hungarian.txt Diff File
mod - lang/strings_icelandic.txt Diff File
mod - lang/strings_italian.txt Diff File
mod - lang/strings_japanese.txt Diff File
mod - lang/strings_korean.txt Diff File
mod - lang/strings_latvian.txt Diff File
mod - lang/strings_lithuanian.txt Diff File
mod - lang/strings_macedonian.txt Diff File
mod - lang/strings_norwegian_bokmal.txt Diff File
mod - lang/strings_norwegian_nynorsk.txt Diff File
mod - lang/strings_occitan.txt Diff File
mod - lang/strings_polish.txt Diff File
mod - lang/strings_portuguese_brazil.txt Diff File
mod - lang/strings_portuguese_standard.txt Diff File
mod - lang/strings_qqq.txt Diff File
mod - lang/strings_ripoarisch.txt Diff File
mod - lang/strings_romanian.txt Diff File
mod - lang/strings_russian.txt Diff File
mod - lang/strings_serbian.txt Diff File
mod - lang/strings_slovak.txt Diff File
mod - lang/strings_slovene.txt Diff File
mod - lang/strings_spanish.txt Diff File
mod - lang/strings_swedish.txt Diff File
mod - lang/strings_swissgerman.txt Diff File
mod - lang/strings_tagalog.txt Diff File
mod - lang/strings_turkish.txt Diff File
mod - lang/strings_ukrainian.txt Diff File
mod - lang/strings_urdu.txt Diff File
mod - lang/strings_volapuk.txt Diff File
mod - login.php Diff File
mod - login_anon.php Diff File
mod - login_cookie_test.php Diff File
mod - login_page.php Diff File
mod - login_select_proj_page.php Diff File
mod - logout_page.php Diff File
mod - lost_pwd.php Diff File
mod - lost_pwd_page.php Diff File
mod - main_page.php Diff File
mod - manage/adm_config_delete.php Diff File
mod - manage/adm_config_report.php Diff File
mod - manage/adm_config_set.php Diff File
mod - manage/adm_permissions_report.php Diff File
mod - manage/columns_copy.php Diff File
mod - manage/columns_inc.php Diff File
mod - manage/config_columns_page.php Diff File
mod - manage/config_columns_reset.php Diff File
mod - manage/config_columns_set.php Diff File
mod - manage/config_email_page.php Diff File
mod - manage/config_email_set.php Diff File
mod - manage/config_revert.php Diff File
mod - manage/config_work_threshold_page.php Diff File
mod - manage/config_work_threshold_set.php Diff File
mod - manage/config_workflow_graph_page.php Diff File
mod - manage/config_workflow_page.php Diff File
mod - manage/config_workflow_set.php Diff File
mod - manage/custom_field_create.php Diff File
mod - manage/custom_field_delete.php Diff File
mod - manage/custom_field_edit_page.php Diff File
mod - manage/custom_field_page.php Diff File
mod - manage/custom_field_proj_add.php Diff File
mod - manage/custom_field_update.php Diff File
mod - manage/overview_page.php Diff File
mod - manage/plugin_install.php Diff File
mod - manage/plugin_page.php Diff File
mod - manage/plugin_uninstall.php Diff File
mod - manage/plugin_update.php Diff File
mod - manage/plugin_upgrade.php Diff File
mod - manage/prof_menu_page.php Diff File
mod - manage/proj_cat_add.php Diff File
mod - manage/proj_cat_copy.php Diff File
mod - manage/proj_cat_delete.php Diff File
mod - manage/proj_cat_edit_page.php Diff File
mod - manage/proj_cat_update.php Diff File
mod - manage/proj_create.php Diff File
mod - manage/proj_create_page.php Diff File
mod - manage/proj_custom_field_add_existing.php Diff File
mod - manage/proj_custom_field_copy.php Diff File
mod - manage/proj_custom_field_remove.php Diff File
mod - manage/proj_custom_field_update.php Diff File
mod - manage/proj_delete.php Diff File
mod - manage/proj_edit_page.php Diff File
mod - manage/proj_page.php Diff File
mod - manage/proj_subproj_add.php Diff File
mod - manage/proj_subproj_delete.php Diff File
mod - manage/proj_update.php Diff File
mod - manage/proj_update_children.php Diff File
mod - manage/proj_user_add.php Diff File
mod - manage/proj_user_copy.php Diff File
mod - manage/proj_user_remove.php Diff File
mod - manage/proj_ver_add.php Diff File
mod - manage/proj_ver_copy.php Diff File
mod - manage/proj_ver_delete.php Diff File
mod - manage/proj_ver_edit_page.php Diff File
mod - manage/proj_ver_update.php Diff File
mod - manage/tags_page.php Diff File
mod - manage/user_create.php Diff File
mod - manage/user_create_page.php Diff File
mod - manage/user_delete.php Diff File
mod - manage/user_edit_page.php Diff File
mod - manage/user_page.php Diff File
mod - manage/user_proj_add.php Diff File
mod - manage/user_proj_delete.php Diff File
mod - manage/user_prune.php Diff File
mod - manage/user_reset.php Diff File
mod - manage/user_update.php Diff File
mod - meta_inc.php Diff File
mod - my_view_inc.php Diff File
mod - my_view_page.php Diff File
mod - news_add.php Diff File
mod - news_edit_page.php Diff File
mod - news_list_page.php Diff File
mod - news_menu_page.php Diff File
mod - news_rss.php Diff File
mod - news_update.php Diff File
mod - news_view_page.php Diff File
mod - permalink_page.php Diff File
mod - plugin.php Diff File
mod - plugin_file.php Diff File
mod - plugins/MantisCoreFormatting/MantisCoreFormatting.php Diff File
mod - plugins/MantisCoreFormatting/lang/strings_afrikaans.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_arabic.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_breton.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_catalan.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_dutch.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_english.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_finnish.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_french.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_galician.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_german.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_greek.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_hebrew.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_hungarian.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_japanese.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_macedonian.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_norwegian_bokmal.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_occitan.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_portuguese_brazil.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_portuguese_standard.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_qqq.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_ripoarisch.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_russian.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_slovak.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_spanish.txt Diff File
mod - plugins/MantisCoreFormatting/lang/strings_swissgerman.txt Diff File
mod - plugins/MantisCoreFormatting/pages/config.php Diff File
mod - plugins/MantisCoreFormatting/pages/config_edit.php Diff File
mod - plugins/MantisGraph/MantisGraph.php Diff File
mod - plugins/MantisGraph/core/Period.php Diff File
mod - plugins/MantisGraph/core/graph_api.php Diff File
mod - plugins/MantisGraph/lang/strings_arabic.txt Diff File
mod - plugins/MantisGraph/lang/strings_arabicegyptianspoken.txt Diff File
mod - plugins/MantisGraph/lang/strings_breton.txt Diff File
mod - plugins/MantisGraph/lang/strings_bulgarian.txt Diff File
mod - plugins/MantisGraph/lang/strings_catalan.txt Diff File
mod - plugins/MantisGraph/lang/strings_chinese_simplified.txt Diff File
mod - plugins/MantisGraph/lang/strings_chinese_traditional.txt Diff File
mod - plugins/MantisGraph/lang/strings_czech.txt Diff File
mod - plugins/MantisGraph/lang/strings_danish.txt Diff File
mod - plugins/MantisGraph/lang/strings_dutch.txt Diff File
mod - plugins/MantisGraph/lang/strings_english.txt Diff File
mod - plugins/MantisGraph/lang/strings_estonian.txt Diff File
mod - plugins/MantisGraph/lang/strings_finnish.txt Diff File
mod - plugins/MantisGraph/lang/strings_french.txt Diff File
mod - plugins/MantisGraph/lang/strings_galician.txt Diff File
mod - plugins/MantisGraph/lang/strings_german.txt Diff File
mod - plugins/MantisGraph/lang/strings_greek.txt Diff File
mod - plugins/MantisGraph/lang/strings_hebrew.txt Diff File
mod - plugins/MantisGraph/lang/strings_hungarian.txt Diff File
mod - plugins/MantisGraph/lang/strings_icelandic.txt Diff File
mod - plugins/MantisGraph/lang/strings_italian.txt Diff File
mod - plugins/MantisGraph/lang/strings_japanese.txt Diff File
mod - plugins/MantisGraph/lang/strings_korean.txt Diff File
mod - plugins/MantisGraph/lang/strings_lithuanian.txt Diff File
mod - plugins/MantisGraph/lang/strings_macedonian.txt Diff File
mod - plugins/MantisGraph/lang/strings_norwegian_bokmal.txt Diff File
mod - plugins/MantisGraph/lang/strings_norwegian_nynorsk.txt Diff File
mod - plugins/MantisGraph/lang/strings_occitan.txt Diff File
mod - plugins/MantisGraph/lang/strings_polish.txt Diff File
mod - plugins/MantisGraph/lang/strings_portuguese_brazil.txt Diff File
mod - plugins/MantisGraph/lang/strings_portuguese_standard.txt Diff File
mod - plugins/MantisGraph/lang/strings_qqq.txt Diff File
mod - plugins/MantisGraph/lang/strings_ripoarisch.txt Diff File
mod - plugins/MantisGraph/lang/strings_romanian.txt Diff File
mod - plugins/MantisGraph/lang/strings_russian.txt Diff File
mod - plugins/MantisGraph/lang/strings_serbian.txt Diff File
mod - plugins/MantisGraph/lang/strings_slovak.txt Diff File
mod - plugins/MantisGraph/lang/strings_spanish.txt Diff File
mod - plugins/MantisGraph/lang/strings_swedish.txt Diff File
mod - plugins/MantisGraph/lang/strings_swissgerman.txt Diff File
mod - plugins/MantisGraph/lang/strings_tagalog.txt Diff File
mod - plugins/MantisGraph/lang/strings_ukrainian.txt Diff File
mod - plugins/MantisGraph/lang/strings_urdu.txt Diff File
mod - plugins/MantisGraph/lang/strings_volapuk.txt Diff File
mod - plugins/MantisGraph/pages/bug_graph_bycategory.php Diff File
mod - plugins/MantisGraph/pages/bug_graph_bystatus.php Diff File
mod - plugins/MantisGraph/pages/bug_graph_page.php Diff File
mod - plugins/MantisGraph/pages/config.php Diff File
mod - plugins/MantisGraph/pages/config_edit.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_bycategory.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_bycategory_pct.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_bydeveloper.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_bypriority.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_bypriority_mix.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_bypriority_pct.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_byreporter.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_byresolution.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_byresolution_mix.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_byresolution_pct.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_byseverity.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_byseverity_mix.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_byseverity_pct.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_bystatus.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_bystatus_pct.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_cumulative_bydate.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_imp_category.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_imp_priority.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_imp_resolution.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_imp_severity.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_imp_status.php Diff File
mod - plugins/MantisGraph/pages/summary_jpgraph_page.php Diff File
mod - plugins/XmlImportExport/ImportXml.php Diff File
mod - plugins/XmlImportExport/ImportXml/Interface.php Diff File
mod - plugins/XmlImportExport/ImportXml/Issue.php Diff File
mod - plugins/XmlImportExport/ImportXml/Mapper.php Diff File
mod - plugins/XmlImportExport/XmlImportExport.php Diff File
mod - plugins/XmlImportExport/lang/strings_arabic.txt Diff File
mod - plugins/XmlImportExport/lang/strings_breton.txt Diff File
mod - plugins/XmlImportExport/lang/strings_catalan.txt Diff File
mod - plugins/XmlImportExport/lang/strings_dutch.txt Diff File
mod - plugins/XmlImportExport/lang/strings_english.txt Diff File
mod - plugins/XmlImportExport/lang/strings_finnish.txt Diff File
mod - plugins/XmlImportExport/lang/strings_french.txt Diff File
mod - plugins/XmlImportExport/lang/strings_galician.txt Diff File
mod - plugins/XmlImportExport/lang/strings_german.txt Diff File
mod - plugins/XmlImportExport/lang/strings_hungarian.txt Diff File
mod - plugins/XmlImportExport/lang/strings_japanese.txt Diff File
mod - plugins/XmlImportExport/lang/strings_macedonian.txt Diff File
mod - plugins/XmlImportExport/lang/strings_norwegian_bokmal.txt Diff File
mod - plugins/XmlImportExport/lang/strings_occitan.txt Diff File
mod - plugins/XmlImportExport/lang/strings_portuguese_standard.txt Diff File
mod - plugins/XmlImportExport/lang/strings_ripoarisch.txt Diff File
mod - plugins/XmlImportExport/lang/strings_russian.txt Diff File
mod - plugins/XmlImportExport/lang/strings_slovak.txt Diff File
mod - plugins/XmlImportExport/lang/strings_spanish.txt Diff File
mod - plugins/XmlImportExport/lang/strings_swissgerman.txt Diff File
mod - plugins/XmlImportExport/pages/export.php Diff File
mod - plugins/XmlImportExport/pages/import.php Diff File
mod - plugins/XmlImportExport/pages/import_action.php Diff File
mod - print_all_bug_options_inc.php Diff File
mod - print_all_bug_options_page.php Diff File
mod - print_all_bug_options_reset.php Diff File
mod - print_all_bug_options_update.php Diff File
mod - print_all_bug_page.php Diff File
mod - print_all_bug_page_word.php Diff File
mod - print_bug_page.php Diff File
mod - print_bugnote_inc.php Diff File
mod - proj_doc_add.php Diff File
mod - proj_doc_add_page.php Diff File
mod - proj_doc_delete.php Diff File
mod - proj_doc_edit_page.php Diff File
mod - proj_doc_page.php Diff File
mod - proj_doc_update.php Diff File
mod - project_page.php Diff File
mod - query_delete.php Diff File
mod - query_delete_page.php Diff File
mod - query_store.php Diff File
mod - query_store_page.php Diff File
mod - query_view_page.php Diff File
mod - return_dynamic_filters.php Diff File
mod - roadmap_page.php Diff File
mod - scripts/send_emails.php Diff File
mod - search.php Diff File
mod - set_project.php Diff File
mod - signup.php Diff File
mod - signup_page.php Diff File
mod - static/javascript/common.js Diff File
mod - summary_page.php Diff File
mod - tag_attach.php Diff File
mod - tag_create.php Diff File
mod - tag_delete.php Diff File
mod - tag_detach.php Diff File
mod - tag_update.php Diff File
mod - tag_update_page.php Diff File
mod - tag_view_page.php Diff File
mod - tests/AllTests.php Diff File
mod - tests/Mantis/AllTests.php Diff File
mod - tests/Mantis/EnumTest.php Diff File
mod - tests/Mantis/StringTest.php Diff File
mod - tests/TestConfig.php Diff File
mod - tests/test_config_get_set.php Diff File
mod - themes/default/common_config.php Diff File
mod - themes/default/status_config.php Diff File
mod - verify.php Diff File
mod - view.php Diff File
mod - view_all_bug_page.php Diff File
mod - view_all_inc.php Diff File
mod - view_all_set.php Diff File
mod - view_filters_page.php Diff File
mod - view_user_page.php Diff File
mod - wiki.php Diff File
mod - workflow_graph_img.php Diff File
mod - xmlhttprequest.php Diff File

master-2.0.x ee96a86b

2013-01-19 20:05

Paul Richards


Details Diff
Set enum strings in one place for lang_get use
mod - core/helper_api.php Diff File
mod - manage/config_workflow_page.php Diff File

master-2.0.x d5add729

2013-01-19 18:46

Paul Richards


Details Diff
replace bulk of lang_get calls with _(gettext) call
mod - account_delete.php Diff File
mod - account_manage_columns_page.php Diff File
mod - account_page.php Diff File
mod - account_prefs_inc.php Diff File
mod - account_prefs_page.php Diff File
mod - account_prof_edit_page.php Diff File
mod - account_prof_menu_page.php Diff File
mod - account_sponsor_page.php Diff File
mod - account_sponsor_update.php Diff File
mod - account_update.php Diff File
mod - admin/db_stats.php Diff File
mod - admin/email_queue.php Diff File
mod - admin/index.php Diff File
mod - billing_inc.php Diff File
mod - billing_page.php Diff File
mod - bug_actiongroup.php Diff File
mod - bug_actiongroup_add_note_inc.php Diff File
mod - bug_actiongroup_attach_tags_inc.php Diff File
mod - bug_actiongroup_ext.php Diff File
mod - bug_actiongroup_page.php Diff File
mod - bug_actiongroup_update_product_build_inc.php Diff File
mod - bug_actiongroup_update_severity_inc.php Diff File
mod - bug_change_status_page.php Diff File
mod - bug_file_delete.php Diff File
mod - bug_file_upload_inc.php Diff File
mod - bug_monitor_list_view_inc.php Diff File
mod - bug_relationship_add.php Diff File
mod - bug_relationship_delete.php Diff File
mod - bug_relationship_graph.php Diff File
mod - bug_reminder_page.php Diff File
mod - bug_report.php Diff File
mod - bug_report_page.php Diff File
mod - bug_revision_drop.php Diff File
mod - bug_revision_view_page.php Diff File
mod - bug_set_sponsorship.php Diff File
mod - bug_sponsorship_list_view_inc.php Diff File
mod - bug_update.php Diff File
mod - bug_update_page.php Diff File
mod - bug_view_inc.php Diff File
mod - bugnote_add.php Diff File
mod - bugnote_add_inc.php Diff File
mod - bugnote_delete.php Diff File
mod - bugnote_edit_page.php Diff File
mod - bugnote_stats_inc.php Diff File
mod - bugnote_view_inc.php Diff File
mod - changelog_page.php Diff File
mod - core/authentication_api.php Diff File
mod - core/bug_group_action_api.php Diff File
mod - core/bug_revision_api.php Diff File
mod - core/bugnote_api.php Diff File
mod - core/category_api.php Diff File
mod - core/classes/Exception/Database/FieldNotFound.class.php Diff File
mod - core/classes/Exception/PHP/TimezoneUpdateFailed.class.php Diff File
mod - core/classes/MantisBug.class.php Diff File
mod - core/classes/MantisError.class.php Diff File
mod - core/columns_api.php Diff File
mod - core/email_api.php Diff File
mod - core/email_queue_api.php Diff File
mod - core/filter_api.php Diff File
mod - core/history_api.php Diff File
mod - core/html_api.php Diff File
mod - core/logging_api.php Diff File
mod - core/news_api.php Diff File
mod - core/print_api.php Diff File
mod - core/profile_api.php Diff File
mod - core/project_api.php Diff File
mod - core/relationship_api.php Diff File
mod - core/string_api.php Diff File
mod - core/tag_api.php Diff File
mod - core/twitter_api.php Diff File
mod - core/user_api.php Diff File
mod - history_inc.php Diff File
mod - issues_rss.php Diff File
mod - login_page.php Diff File
mod - login_select_proj_page.php Diff File
mod - lost_pwd.php Diff File
mod - lost_pwd_page.php Diff File
mod - main_page.php Diff File
mod - manage/adm_config_delete.php Diff File
mod - manage/adm_config_report.php Diff File
mod - manage/adm_permissions_report.php Diff File
mod - manage/columns_inc.php Diff File
mod - manage/config_columns_page.php Diff File
mod - manage/config_email_page.php Diff File
mod - manage/config_revert.php Diff File
mod - manage/config_work_threshold_page.php Diff File
mod - manage/config_workflow_graph_page.php Diff File
mod - manage/config_workflow_page.php Diff File
mod - manage/config_workflow_set.php Diff File
mod - manage/custom_field_delete.php Diff File
mod - manage/custom_field_edit_page.php Diff File
mod - manage/custom_field_page.php Diff File
mod - manage/overview_page.php Diff File
mod - manage/plugin_page.php Diff File
mod - manage/plugin_uninstall.php Diff File
mod - manage/proj_cat_add.php Diff File
mod - manage/proj_cat_delete.php Diff File
mod - manage/proj_cat_edit_page.php Diff File
mod - manage/proj_create_page.php Diff File
mod - manage/proj_custom_field_remove.php Diff File
mod - manage/proj_delete.php Diff File
mod - manage/proj_edit_page.php Diff File
mod - manage/proj_page.php Diff File
mod - manage/proj_user_remove.php Diff File
mod - manage/proj_ver_delete.php Diff File
mod - manage/proj_ver_edit_page.php Diff File
mod - manage/tags_page.php Diff File
mod - manage/user_create.php Diff File
mod - manage/user_create_page.php Diff File
mod - manage/user_delete.php Diff File
mod - manage/user_edit_page.php Diff File
mod - manage/user_page.php Diff File
mod - manage/user_proj_delete.php Diff File
mod - manage/user_prune.php Diff File
mod - manage/user_reset.php Diff File
mod - manage/user_update.php Diff File
mod - my_view_inc.php Diff File
mod - my_view_page.php Diff File
mod - news_add.php Diff File
mod - news_edit_page.php Diff File
mod - news_list_page.php Diff File
mod - news_menu_page.php Diff File
mod - news_rss.php Diff File
mod - news_update.php Diff File
mod - news_view_page.php Diff File
mod - permalink_page.php Diff File
mod - plugins/MantisCoreFormatting/pages/config.php Diff File
mod - plugins/MantisGraph/core/Period.php Diff File
mod - plugins/MantisGraph/core/graph_api.php Diff File
mod - plugins/MantisGraph/pages/bug_graph_bycategory.php Diff File
mod - plugins/MantisGraph/pages/bug_graph_bystatus.php Diff File
mod - plugins/MantisGraph/pages/config.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_bycategory.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_bydeveloper.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_bypriority.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_byreporter.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_byresolution.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_byseverity.php Diff File
mod - plugins/MantisGraph/pages/summary_graph_bystatus.php Diff File
mod - plugins/MantisGraph/pages/summary_jpgraph_page.php Diff File
mod - plugins/XmlImportExport/XmlImportExport.php Diff File
mod - plugins/XmlImportExport/pages/import.php Diff File
mod - print_all_bug_options_inc.php Diff File
mod - print_all_bug_page.php Diff File
mod - print_all_bug_page_word.php Diff File
mod - print_bug_page.php Diff File
mod - print_bugnote_inc.php Diff File
mod - proj_doc_add.php Diff File
mod - proj_doc_add_page.php Diff File
mod - proj_doc_delete.php Diff File
mod - proj_doc_edit_page.php Diff File
mod - proj_doc_page.php Diff File
mod - proj_doc_update.php Diff File
mod - project_page.php Diff File
mod - query_delete.php Diff File
mod - query_delete_page.php Diff File
mod - query_store.php Diff File
mod - query_store_page.php Diff File
mod - query_view_page.php Diff File
mod - roadmap_page.php Diff File
mod - set_project.php Diff File
mod - signup.php Diff File
mod - signup_page.php Diff File
mod - summary_page.php Diff File
mod - tag_attach.php Diff File
mod - tag_delete.php Diff File
mod - tag_update_page.php Diff File
mod - tag_view_page.php Diff File
mod - themes/default/common_config.php Diff File
mod - view_all_bug_page.php Diff File
mod - view_all_inc.php Diff File
mod - view_filters_page.php Diff File
mod - view_user_page.php Diff File

master-1.2.x 512a5af8

2013-01-19 17:31

dregad


Details Diff
Display of match_type filter property for unknown types

Prior to this, if for any reason the filter's match type property was
not one of the predefined types (i.e. 'any' or 'all'), the code would
default to 'all', but display a blank string on the filter page. This is
confusing to users, so the display now matches the filter's actual
behavior.

Fixes 0015389
Affected Issues
0015389
mod - core/filter_api.php Diff File

master 5f641fc7

2013-01-19 17:31

dregad


Details Diff
Display of match_type filter property for unknown types

Prior to this, if for any reason the filter's match type property was
not one of the predefined types (i.e. 'any' or 'all'), the code would
default to 'all', but display a blank string on the filter page. This is
confusing to users, so the display now matches the filter's actual
behavior.

Fixes 0015389
Affected Issues
0015389
mod - core/filter_api.php Diff File

master-1.2.x dbf923c3

2013-01-19 17:22

dregad


Details Diff
Update match_type parameter to be XSS-safe by itself

Use of gpc_get_int() instead of gpc_get_string() prevents malicious
users from passing arbitrary strings as parameter.

Fixes 0015388
Affected Issues
0015388
mod - core/filter_api.php Diff File
mod - search.php Diff File
mod - view_all_set.php Diff File

master 4362aa14

2013-01-19 17:22

dregad


Details Diff
Update match_type parameter to be XSS-safe by itself

Use of gpc_get_int() instead of gpc_get_string() prevents malicious
users from passing arbitrary strings as parameter.

Fixes 0015388
Affected Issues
0015388
mod - core/filter_api.php Diff File
mod - search.php Diff File
mod - view_all_set.php Diff File

master 42627a65

2013-01-19 09:40

rombert


Details Diff
Revert "filter api: always treat FILTER_PROPERTY_MATCH_TYPE as an int value"

This reverts commit 45f9e746fb9a42e74b668211372d9e45db3e7b6c.

This fix reopens the reported vulnerability therefore it is reverted.
mod - core/filter_api.php Diff File
mod - view_all_set.php Diff File

master-1.2.x 26c8ca22

2013-01-19 09:39

rombert


Details Diff
Revert "filter api: always treat FILTER_PROPERTY_MATCH_TYPE as an int value"

This reverts commit 610da6ecda08239187bc12bf9bf35ba4d27f1920.

This fix reopens the reported vulnerability therefore it is reverted.
mod - core/filter_api.php Diff File
mod - view_all_set.php Diff File

master-1.2.x 7df30a9e

2013-01-18 17:49

dhx


Details Diff
Fix 0015384: summary.php XSS vulnerability in MantisBT 1.2.12 only

Roland Becker (MantisBT Developer) discovered a XSS vulnerability
introduced in MantisBT 1.2.12 with the display of category/project names
on the summary.php page.

A malicious MantisBT user holding privileged manager/administrator
permissions could create a category or project name that contains
JavaScript code. Any user visiting summary.php from that point on may
then be exposed to having the malicious JavaScript execute within their
browser environment.

The severity of this issue is limited by the need to hold privileged
manager/administrator permissions in order to modify category and
project names. However -- there are many use cases where MantisBT
installations can have hundreds of sub-projects, each managed by
different people/parties that can not or should not be fully trusted.

Refer to previous commits 3ca8a164 and 6ec3f693 to trace back the origin
of this vulnerability.
Affected Issues
0015384
mod - core/summary_api.php Diff File

master-1.2.x 6492038e

2013-01-18 17:32

dregad


Details Diff
Updated CREDITS file in preparation of 1.2.13 release
mod - doc/CREDITS Diff File

master 45f9e746

2013-01-18 15:22

rombert


Details Diff
filter api: always treat FILTER_PROPERTY_MATCH_TYPE as an int value

Based on @dregad's comments, this follows up on @dhx's fix.

Fixes 0015373: XSS vulnerability
Affected Issues
0015373
mod - core/filter_api.php Diff File
mod - view_all_set.php Diff File

master-1.2.x 610da6ec

2013-01-18 15:22

rombert


Details Diff
filter api: always treat FILTER_PROPERTY_MATCH_TYPE as an int value

Based on @dregad's comments, this follows up on @dhx's fix.

Fixes 0015373: XSS vulnerability
Affected Issues
0015373
mod - core/filter_api.php Diff File
mod - view_all_set.php Diff File
 First  Prev  1 2 3 ... 70 ... 140 ... 210 ... 280 ... 349 350 351 352 353 354 355 ... 420 ... 490 ... 560 ... 630 ... 700 ... 746 747 748  Next  Last