CVS log for ports/www/apache13-ssl/files/Attic/patch-secfix-CAN-2005-3352
Up to [FreeBSD] / ports / www / apache13-ssl / files
Request diff between arbitrary revisions
Keyword substitution: kv
Default branch: MAIN
Revision 1.2
Sun Mar 18 17:13:58 2007 UTC (4 years, 10 months ago) by clement
Branches: MAIN
CVS tags: HEAD
FILE REMOVED
Changes since revision 1.1: +0 -0 lines
- Update to 1.3.37-1.57
Revision 1.1: download - view: text, markup, annotated - select for diffs
Mon Dec 12 20:31:53 2005 UTC (6 years, 1 month ago) by clement
Branches: MAIN
CVS tags: RELEASE_6_2_0, RELEASE_6_1_0, RELEASE_5_5_0, RELEASE_4_EOL
SECURITY: CVE-2005-3352 (cve.mitre.org) mod_imap: Escape untrusted referer header before outputting in HTML to avoid potential cross-site scripting. Change also made to ap_escape_html so we escape quotes. Reported by JPCERT. [Mark Cox] Reported by: simon
