aboutsummaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Bumped version to 4.0.16release-4.0.16bugzilla-4.0.16David Lawrence2015-01-212-4/+4
* Bug 1090275: WebServices modules should maintain a whitelist of methods that ...David Lawrence2015-01-218-0/+64
* Bug 1079065: [SECURITY] Always use the 3 arguments form for open() to prevent...Gervase Markham2015-01-2112-19/+19
* Fix typoFrédéric Buclin2015-01-191-2/+2
* Bug 1118988: Release notes for 4.0.16David Lawrence2015-01-191-0/+16
* Bug 1085182: Bugzilla::Bug->check must check that a bug ID is defined when it...Frédéric Buclin2015-01-051-7/+7
* Bug 1097798: Do not display the resolution in the dependency tree for open bu...Frédéric Buclin2014-11-191-2/+5
* Bug 1082887: comments made when setting a flag from the attachment details pa...Byron Jones2014-10-161-4/+9
* Bump version post-releaseDavid Lawrence2014-10-062-2/+2
* Bump version to 4.0.15release-4.0.15bugzilla-4.0.15David Lawrence2014-10-062-3/+3
* Bug 1054702: CSV export vulnerable to formulae injectionSimon Green2014-10-062-4/+8
* Bug 1064140: [SECURITY] Private comments can be shown to flagmail recipients ...Simon Green2014-10-063-18/+38
* Bug 1074980: Forbid the { foo => $cgi->param() } syntax to prevent data overrideFrédéric Buclin2014-10-061-1/+32
* Bug 1075578: [SECURITY] Improper filtering of CGI argumentsFrédéric Buclin2014-10-0611-43/+44
* Bug 1072494: Release notes for 4.0.15David Lawrence2014-10-061-0/+6
* Bump version post-releaseDavid Lawrence2014-07-242-4/+2
* Bump version to 4.0.14 (corrected)release-4.0.14bugzilla-4.0.14David Lawrence2014-07-242-0/+2
* Bug 1036213 - (CVE-2014-1546) add '/**/' before jsonrpc.cgi callback to avoid...Simon Green2014-07-241-2/+3
* Bump version to 4.0.14David Lawrence2014-07-242-3/+3
* Bug 1042091 - Release notes for 4.0.14David Lawrence2014-07-241-0/+6
* Bug 1011250 - Updates IRC notification text to include commit message and als...David Lawrence2014-05-151-4/+9
* Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ciDavid Lawrence2014-05-151-1/+1
* Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ciDavid Lawrence2014-05-141-1/+1
* Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ciDavid Lawrence2014-05-081-0/+6
* Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ciDavid Lawrence2014-05-071-3/+1
* Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ciDavid Lawrence2014-05-071-4/+4
* Bug 995209 - Create a Build.PL script using Module::Build for testing/install...David Lawrence2014-05-021-1/+1
* Bug 983275 - Switch Bugzilla's CI testing from Tinderbox to travis-ciDavid Lawrence2014-05-021-0/+39
* Bug 995209 - Create a Build.PL script using Module::Build for testing/install...David Lawrence2014-05-012-0/+114
* Bumped version post-releaseDavid Lawrence2014-04-212-2/+2
* Bump version to 4.0.13release-4.0.13bugzilla-4.0.13David Lawrence2014-04-182-3/+3
* Bug 998484: Release notes for Bugzilla 4.0.13Frédéric Buclin2014-04-181-0/+7
* Bug 998323 - URLs pasted in comments are no longer displayedDavid Lawrence2014-04-181-15/+12
* Bumped version post-releaseDavid Lawrence2014-04-172-2/+2
* Bumped version to 4.0.12release-4.0.12bugzilla-4.0.12David Lawrence2014-04-172-4/+4
* Bug 968576: [SECURITY] Dangerous control characters allowed in Bugzilla textManish Goregaokar2014-04-174-2/+17
* Fix POD to make tests happyFrédéric Buclin2014-04-172-0/+6
* Bug 996169: Release notes for Bugzilla 4.0.12Frédéric Buclin2014-04-151-0/+6
* Copied over .bzrignore to .gitignoreDavid Lawrence2014-03-141-0/+32
* Bug 942599: Documentation about possible_duplicates() lists 'products' as arg...Frédéric Buclin2013-12-051-1/+1
* Bump version post-releaseDave Lawrence2013-10-171-1/+1
* Bump version to 4.0.11release-4.0.11bugzilla-4.0.11Dave Lawrence2013-10-162-3/+3
* Bug 924802: (CVE-2013-1742) [SECURITY] (XSS) "id" and "sortkey" are not sanit...Frédéric Buclin2013-10-162-8/+4
* Bug 913904: (CVE-2013-1734) [SECURITY] CSRF when updating attachmentsFrédéric Buclin2013-10-162-8/+15
* Bug 906745 - In MySQL, tokens are not case-sensitive, reducing total entropy ...Dave Lawrence2013-10-161-1/+1
* Bug 907438 - In MySQL, login cookie checking is not case-sensitive, reducing ...Dave Lawrence2013-10-161-3/+3
* Bug 906745 - In MySQL, tokens are not case-sensitive, reducing total entropy ...Dave Lawrence2013-10-163-8/+24
* Bug 912639: Release notes for Bugzilla 4.0.11Frédéric Buclin2013-10-121-0/+21
* Bug 902515: Internet Explorer 11 receives multipart/x-mixed-replace content f...Frédéric Buclin2013-08-091-1/+1
* Bug 901620 - Grammar error in the documentationSunil Joshi2013-08-071-1/+1