Dotclear


Ignore:
Files:
4 edited

Legend:

Unmodified
Added
Removed
  • .hgtags

    r2714 r2742  
    20201f8978ee39fc70bf9a6c345cf3b550722b819173 2.6.2 
    2121121f94747a10af7f58a88c00537eafc4e0d29685 2.6.3 
     2280d565483595acca5b1d9e149aa8a2a9fe5983a6 2.6.4 
  • CHANGELOG

    r2718 r2742  
     1Dotclear 2.6.4 - 2014-08-18 
     2=========================================================== 
     3* Security fix: Sanitize search request. Thanks to Takayuki Uchiyama 
     4* Security fix: Strenghened xmlrpc (see http://www.breaksec.com/?p=6362) 
     5 
    16Dotclear 2.6.3 - 2014-05-16 
    27=========================================================== 
  • admin/search.php

    r2720 r2742  
    2929if ($q) 
    3030{ 
     31     $q = html::escapeHTML($q); 
     32 
    3133     $params = array(); 
    3234 
     
    9496'<form action="'.$core->adminurl->get("admin.search").'" method="get">'. 
    9597'<div class="fieldset"><h3>'.__('Search options').'</h3>'. 
    96 '<p><label for="q">'.__('Query:').' </label>'.form::field('q',30,255,html::escapeHTML($q)).'</p>'. 
     98'<p><label for="q">'.__('Query:').' </label>'.form::field('q',30,255,$q).'</p>'. 
    9799'<p><label for="qtype1" class="classic">'.form::radio(array('qtype','qtype1'),'p',$qtype == 'p').' '.__('Search in entries').'</label> '. 
    98100'<label for="qtype2" class="classic">'.form::radio(array('qtype','qtype2'),'c',$qtype == 'c').' '.__('Search in comments').'</label></p>'. 
  • admin/xmlrpc.php

    r2566 r2730  
    2727} 
    2828 
     29# Avoid plugins warnings, set a default blog 
     30$core->setBlog($blog_id); 
     31 
    2932# Loading plugins 
    3033$core->plugins->loadModules(DC_PLUGINS_ROOT); 
Note: See TracChangeset for help on using the changeset viewer.

Sites map