CVS log for ports/www/apache20/files/Attic/patch-secfix-CAN-2005-3352
Up to [FreeBSD] / ports / www / apache20 / files
Request diff between arbitrary revisions
Keyword substitution: kv
Default branch: MAIN
Revision 1.2
Mon May 1 11:33:17 2006 UTC (5 years, 9 months ago) by clement
Branches: MAIN
CVS tags: HEAD
FILE REMOVED
Changes since revision 1.1: +0 -0 lines
Oops I forgot to "cvs rm" a secfix Spotted by: krion
Revision 1.1: download - view: text, markup, annotated - select for diffs
Mon Dec 12 20:35:19 2005 UTC (6 years, 1 month ago) by clement
Branches: MAIN
CVS tags: RELEASE_6_1_0, RELEASE_5_5_0
SECURITY: CVE-2005-3352 (cve.mitre.org)
mod_imap: Escape untrusted referer header before outputting in HTML
to avoid potential cross-site scripting. Change also made to
ap_escape_html so we escape quotes. Reported by JPCERT.
[Mark Cox]
Reported by: simon
