Bug#389361: XSS vulnerability fixed

2006-09-27 Thread Recai Oktaş
* Stefan Ritt [2006-09-27 23:09:27+0200] > The reported XSS vulnerability has been fixed in SVN revision 1719 of > elog by not allowing HTML mode by default. This mode has to be enabled > explicitly by setting "Allowed encoding = 7". Hi Stefan, Thanks for the fix! I haven't checked the stable

Bug#389361: XSS vulnerability fixed

2006-09-27 Thread Stefan Ritt
The reported XSS vulnerability has been fixed in SVN revision 1719 of elog by not allowing HTML mode by default. This mode has to be enabled explicitly by setting "Allowed encoding = 7". Cheers, Stefan -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble?