[dokuwiki] darcs changes 2006-09-27
- From: andi@xxxxxxxxxxxxxx (Andreas Gohr)
- To: dokuwiki@xxxxxxxxxxxxx
- Date: Wed, 27 Sep 2006 04:00:01 +0200 (CEST)
Good Morning!
This are the darcs changes for DokuWiki committed
yesterday. Please test them and report bugs.
---------------------------------------------------------------------
Tue Sep 26 22:05:51 CEST 2006 Andreas Gohr <andi[at]splitbrain.org>
* security fixes for fetch.php #924 #962
Fixes a shell injection and a DOS vulnerability
Tue Sep 26 21:24:20 CEST 2006 Andreas Gohr <andi[at]splitbrain.org>
* wordblock enhancement
The default wordblock.conf provided by the guys at chonqed.org matches agaist
URLS beginning with http. But DokuWiki also links simple www.example.com
links.
Spammers used this method to place blacklisted URLs in the Wiki.
This patch constructs full URLs from these shortcut-URLs before applying the
blacklist regexp.
The patch also fixes a problem with the toolbar not appearing when the
blacklist
hit and denied saving.
---------------------------------------------------------------------
Single patches can be downloaded from
http://dev.splitbrain.org/darcs/index.cgi/dokuwiki/?c=patches
Bye,
your darcs changlog mailer
--
DokuWiki mailing list - more info at
http://wiki.splitbrain.org/wiki:mailinglist
Other related posts:
- » [dokuwiki] darcs changes 2006-09-27