Details

    Description

      Attached patch escapes some more output show to user. Fixes XSS exploits.
      Also added a wrapper function (escape()) for the htmlspecialchars (long and boring to type..). Let me know if another name may be more suitable for the function. I did not change all the htmlspecialchars yet, waste of time if this does not get commited

      Other changes;
      Changed $_POST/GET into $vars in multiple files in html/
      Removed mres for place it was not needed or was redundant.
      Fixed a typo in generic_definition.inc.php
      Check if bill name is set when adding bill, if not don't add an empty entry to DB

      Attachments

        Activity

          [OBS-1152] Security fixes + other small fixes
          landy Mike Stupalov made changes -
          Workflow Original: classic default workflow [ 12037 ] New: Observium workflow [ 14389 ]
          landy Mike Stupalov made changes -
          Status Original: Resolved [ 5 ] New: Closed [ 6 ]
          landy Mike Stupalov made changes -
          Resolution New: Fixed [ 1 ]
          Status Original: Open [ 1 ] New: Resolved [ 5 ]

          Commited in r6207.

          Note, some changes not compatible with patch, you can get svn errors.

          landy Mike Stupalov added a comment - Commited in r6207. Note, some changes not compatible with patch, you can get svn errors.
          kentbjoh Kent Johannessen made changes -
          Attachment Original: security-and-misc-fixesv2.patch [ 12253 ]
          kentbjoh Kent Johannessen made changes -
          Attachment Original: security-and-misc-fixesv2.patch [ 12252 ]
          kentbjoh Kent Johannessen made changes -
          Attachment New: security-and-misc-fixesv2.patch [ 12254 ]

          another update.. damn this is hard. time to sleep i think

          kentbjoh Kent Johannessen added a comment - another update.. damn this is hard. time to sleep i think
          kentbjoh Kent Johannessen made changes -
          Attachment New: security-and-misc-fixesv2.patch [ 12253 ]

          see updated - went with escape_html()

          kentbjoh Kent Johannessen added a comment - see updated - went with escape_html()

          People

            landy Mike Stupalov
            kentbjoh Kent Johannessen
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: