Skip to content
Snippets Groups Projects
  1. May 07, 2014
  2. May 05, 2014
    • Jared Hancock's avatar
      oops: Fixup bad merge · 21949b25
      Jared Hancock authored
      Previously, there was a bug in the ORM where magic properties would need to
      be declared in the model class.
      21949b25
  3. May 03, 2014
  4. May 02, 2014
    • Jared Hancock's avatar
      security: Remove potential XSS vulnerability · 9916214f
      Jared Hancock authored
      The ThreadEntryWidget has a potential cross site scripting (XSS)
      vulnerability if data was posted directly to the page hosting the widget
      
      Vulnerable URLs:
      view.php, open.php, scp/open.php, scp/tickets.php
      
      The content received in the HTTP POST is now correctly escaped when it is
      echoed back to the user agent.
      9916214f
  5. May 01, 2014
  6. Apr 30, 2014
    • Peter Rotich's avatar
      Merge pull request #825 from greezybacon/issue/tnef-bad-rewind · d4fed2cd
      Peter Rotich authored
      
      tnef: Fix major issue iterating over attar streams
      
      Reviewed-By: default avatarPeter Rotich <peter@osticket.com>
      d4fed2cd
    • Jared Hancock's avatar
      tnef: Fix major issue iterating over attr streams · 34d8d0b4
      Jared Hancock authored
      The original logic would read the count of attributes in the stream and then
      read the first attribute in the constructor of TnefAttributeStreamReader.
      Then the iterator interface would call ::rewind() before iterating to the
      first item. rewind() set the @pos attribute to zero, which would cause the
      attribute count (4-byte int) to be interpreted incorrectly as part of the
      first attribute.
      
      The new logic sets the position at 4 after rewind()ing, and does not read
      the first attribute twice. It also properly detects the end of the attribute
      stream by the number of attributes advertised as the first four bytes of the
      stream (read into the @count attribute initially).
      34d8d0b4
  7. Apr 29, 2014
  8. Apr 28, 2014
  9. Apr 25, 2014
  10. Apr 24, 2014
  11. Apr 23, 2014
  12. Apr 18, 2014
  13. Apr 16, 2014
  14. Apr 15, 2014
  15. Apr 14, 2014
    • Jared Hancock's avatar
      Fixup merging of email recipients · 0c32eabb
      Jared Hancock authored
      This stems from a confusing similarity between the + operator for arrays
      and array_merge() in php. Adding arrays will ignore items in the RHS where
      keys are present in the LHS. Therefore, when adding numerically indexed
      arrays together, only items on the RHS that have a key higher than the
      greatest key on the LHS will be included.
      0c32eabb
Loading