Skip to content
Snippets Groups Projects
  1. Aug 29, 2014
  2. Aug 27, 2014
  3. Aug 22, 2014
  4. Aug 15, 2014
  5. Aug 07, 2014
  6. Jul 29, 2014
    • Jared Hancock's avatar
      forms: Phone numbers with no digits = invalid · a24ec590
      Jared Hancock authored
      Previously, the characters would be removed and the data would be considered
      empty which would bypass validation and clear the phone number on save
      rather than triggering a validation error.
      a24ec590
  7. Jul 28, 2014
  8. Jul 18, 2014
  9. Jul 15, 2014
  10. Jul 09, 2014
  11. Jul 07, 2014
  12. Jul 02, 2014
  13. Jun 30, 2014
  14. Jun 27, 2014
  15. Jun 16, 2014
  16. May 26, 2014
  17. May 23, 2014
  18. May 22, 2014
  19. May 09, 2014
  20. May 02, 2014
    • Jared Hancock's avatar
      security: Remove potential XSS vulnerability · 9916214f
      Jared Hancock authored
      The ThreadEntryWidget has a potential cross site scripting (XSS)
      vulnerability if data was posted directly to the page hosting the widget
      
      Vulnerable URLs:
      view.php, open.php, scp/open.php, scp/tickets.php
      
      The content received in the HTTP POST is now correctly escaped when it is
      echoed back to the user agent.
      9916214f
  21. May 01, 2014
  22. Apr 25, 2014
  23. Apr 24, 2014
  24. Apr 01, 2014
  25. Mar 25, 2014
Loading