Skip to content
Snippets Groups Projects
  1. Aug 27, 2014
  2. Aug 22, 2014
  3. Aug 15, 2014
  4. Aug 07, 2014
  5. Jul 29, 2014
    • Jared Hancock's avatar
      forms: Phone numbers with no digits = invalid · a24ec590
      Jared Hancock authored
      Previously, the characters would be removed and the data would be considered
      empty which would bypass validation and clear the phone number on save
      rather than triggering a validation error.
      a24ec590
  6. Jul 28, 2014
  7. Jul 18, 2014
  8. Jul 15, 2014
  9. Jul 09, 2014
  10. Jul 07, 2014
  11. Jul 02, 2014
  12. Jun 30, 2014
  13. Jun 27, 2014
  14. Jun 16, 2014
  15. May 26, 2014
  16. May 23, 2014
  17. May 22, 2014
  18. May 09, 2014
  19. May 02, 2014
    • Jared Hancock's avatar
      security: Remove potential XSS vulnerability · 9916214f
      Jared Hancock authored
      The ThreadEntryWidget has a potential cross site scripting (XSS)
      vulnerability if data was posted directly to the page hosting the widget
      
      Vulnerable URLs:
      view.php, open.php, scp/open.php, scp/tickets.php
      
      The content received in the HTTP POST is now correctly escaped when it is
      echoed back to the user agent.
      9916214f
  20. May 01, 2014
  21. Apr 25, 2014
  22. Apr 24, 2014
  23. Apr 01, 2014
  24. Mar 25, 2014
  25. Feb 07, 2014
  26. Jan 17, 2014
  27. Jan 14, 2014
  28. Jan 10, 2014
Loading