]> git.ipfire.org Git - thirdparty/bugzilla.git/commit
[SECURITY] Bug 214290: A user with 'editproducts' privileges (i.e. usually an adminis...
authorjustdave%syndicomm.com <>
Mon, 3 Nov 2003 11:44:38 +0000 (11:44 +0000)
committerjustdave%syndicomm.com <>
Mon, 3 Nov 2003 11:44:38 +0000 (11:44 +0000)
commit3721adcbb24af056e245622f2fc4bdfabe97965e
treec041f3025d31f156342ad97754cff33699f397cd
parent915041acc095f839a59127b936392bdd46b95da8
[SECURITY] Bug 214290: A user with 'editproducts' privileges (i.e. usually an administrator) can select arbitrary SQL to be run by the nightly statistics cron job (collectstats.pl), by giving a product a special name.
Patch by Dave Miller <justdave@bugzilla.org>
r= gerv, bbaetz   a= justdave
collectstats.pl