]> git.ipfire.org Git - thirdparty/bugzilla.git/commit
[SECURITY] Bug 219044: A user with 'editkeywords' privileges (i.e. usually an adminis...
authorjustdave%syndicomm.com <>
Mon, 3 Nov 2003 11:46:55 +0000 (11:46 +0000)
committerjustdave%syndicomm.com <>
Mon, 3 Nov 2003 11:46:55 +0000 (11:46 +0000)
commita645ea4e5cb30680020e27842527009002cc66ee
treeeded6f54a60ca9baf9d3c09ab4db0cade6e4add5
parent3721adcbb24af056e245622f2fc4bdfabe97965e
[SECURITY] Bug 219044: A user with 'editkeywords' privileges (i.e. usually an administrator) can inject arbitrary SQL via the URL used to edit an existing keyword.
Patch by Joel Peshkin <bugreport@peshkin.net>
r= justdave, zach   a= justdave
editkeywords.cgi