dolibarr-git
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Dolibarr-git] [Dolibarr/dolibarr] 212b3b: Revert "Fix: add special test


From: Laurent Destailleur
Subject: [Dolibarr-git] [Dolibarr/dolibarr] 212b3b: Revert "Fix: add special test"
Date: Mon, 09 Apr 2012 16:32:00 -0700

  Branch: refs/heads/develop
  Home:   https://github.com/Dolibarr/dolibarr
  Commit: 212b3bd60ea12b43adcc105a0a791bb9480fd292
      
https://github.com/Dolibarr/dolibarr/commit/212b3bd60ea12b43adcc105a0a791bb9480fd292
  Author: Laurent Destailleur <address@hidden>
  Date:   2012-04-09 (Mon, 09 Apr 2012)

  Changed paths:
    M htdocs/core/lib/functions.lib.php

  Log Message:
  -----------
  Revert "Fix: add special test"

This reverts commit ef0e6956b358a825f8fa3071ac7599ac322e562e.


  Commit: 4cb6ec76ee0887c5c6c788f09dac1581acdc14a8
      
https://github.com/Dolibarr/dolibarr/commit/4cb6ec76ee0887c5c6c788f09dac1581acdc14a8
  Author: Laurent Destailleur <address@hidden>
  Date:   2012-04-09 (Mon, 09 Apr 2012)

  Changed paths:
    M htdocs/admin/tools/export.php
  M htdocs/core/lib/functions.lib.php

  Log Message:
  -----------
  Revert "Fix: sql injection"

This reverts commit 8c3158cf28a6711d61fd8b3dacccc6ad746be8d0.


  Commit: 1571134f7dce273488600dab742a9972f929bb93
      
https://github.com/Dolibarr/dolibarr/commit/1571134f7dce273488600dab742a9972f929bb93
  Author: Laurent Destailleur <address@hidden>
  Date:   2012-04-09 (Mon, 09 Apr 2012)

  Changed paths:
    M htdocs/admin/tools/export.php

  Log Message:
  -----------
  Revert "Fix: security"

This reverts commit 380a8109e89b72be765013a505acf10a4a5e1759.


  Commit: 37ce5d9fca25ad67a4988f3fd733bd76b631a431
      
https://github.com/Dolibarr/dolibarr/commit/37ce5d9fca25ad67a4988f3fd733bd76b631a431
  Author: Laurent Destailleur <address@hidden>
  Date:   2012-04-09 (Mon, 09 Apr 2012)

  Changed paths:
    M htdocs/admin/tools/export.php

  Log Message:
  -----------
  Revert code because it does not fix security hole completely. Also it
does work on origin but at a transition level.
Sanitizing for command line data must not appears inside a function used
for http data. I prefer fixing this at the source and also using a rule
that clean all attacks completely instead of a rule that clean "most
problem but not all".


Compare: https://github.com/Dolibarr/dolibarr/compare/ef0e695...37ce5d9

reply via email to

[Prev in Thread] Current Thread [Next in Thread]