1
0

escape more

This commit is contained in:
Garvin Hicking
2013-02-08 08:38:48 +01:00
parent 63ba9b0431
commit 19dad1f586
17 changed files with 20 additions and 18 deletions

View File

@ -14,7 +14,9 @@ Version 1.7 ()
* Media database: Escape more Cookie values to prevent storing
possible XSS (http://board.s9y.org/viewtopic.php?f=3&t=19142).
Escape hotlinked media filename.
Escape hotlinked media filename. Escape importer host name error
Thanks to GreenSun from the forums for bringing this to attention,
originally reported by Dshellnoi Unix
* rc2: Alter entries.tpl to add the line:
{assign var="entry" value=$entry scope="parent"}