aboutsummaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Bug 802204 (CVE-2012-4197): [SECURITY] Marking an attachment you cannot see a...Frédéric Buclin2012-11-131-2/+1
* Bug 731178 (CVE-2012-4199): [SECURITY] field-events.js.tmpl discloses product...Frédéric Buclin2012-11-133-4/+10
* Bug 805649: Release notes for Bugzilla 4.0.9Frédéric Buclin2012-10-301-0/+21
* Bug 790215 - Flag names are not properly escaped when displayed on confirm us...Reed Loden2012-09-112-2/+1
* Bug 786352: Release notes for Bugzilla 4.0.8Frédéric Buclin2012-08-291-0/+11
* Bug 785917: Custom field descriptions are not properly escaped when displayed...Frédéric Buclin2012-08-272-2/+1
* Bug 777675: Release notes for Bugzilla 4.0.7Frédéric Buclin2012-07-261-0/+22
* Bug 756314: Fix dropping of unique matches when the "confirm page" page is di...Byron Jones2012-05-291-4/+4
* Bug 745397: (CVE-2012-0466) [SECURITY] The JS template for buglists permits a...Frédéric Buclin2012-04-181-37/+0
* Bug 741077: Update relnotes for 4.0.6Frédéric Buclin2012-04-171-1/+1
* Bug 741077: Release notes for Bugzilla 4.0.6Frédéric Buclin2012-04-121-0/+15
* Bug 725663 - (CVE-2012-0453) [SECURITY] CSRF vulnerability in the XML-RPC API...Dave Lawrence2012-02-221-0/+5
* Bug 727893: Release notes for Bugzilla 4.0.5Frédéric Buclin2012-02-171-0/+16
* Bug 722161: Clickjacking is possible in "View All" with HTML attachmentsFrédéric Buclin2012-02-081-4/+16
* Bug 718319: (CVE-2012-0440) [SECURITY] JSON-RPC permits to bypass token check...Frédéric Buclin2012-01-311-0/+4
* Bug 714472: (CVE-2012-0448) [SECURITY] utf8 homoglyphs are allowed in email a...Frédéric Buclin2012-01-312-5/+3
* Bug 720752 - Release notes for Bugzilla 4.0.4Dave Lawrence2012-01-271-10/+35
* Bug 715650 - User auto-completion does not work in request.cgi for requester ...Dave Lawrence2012-01-111-1/+2
* Bug 716283: Clickjacking in the attachment "Details" page allows to bypass to...Frédéric Buclin2012-01-102-4/+19
* Bug 715705: User auto-completion doesn't work for watched users in the email ...Frédéric Buclin2012-01-061-1/+2
* Bug 714664: The content of the "emailregexpdesc" parameter is not escaped whe...Frédéric Buclin2012-01-062-2/+2
* Bug 713345: Release notes for Bugzilla 4.0.3Frédéric Buclin2011-12-281-1/+53
* Bug 277073: Make whining trap errors thrown by Search.pmFrédéric Buclin2011-11-281-0/+4
* Fix missing-space bugs in error messages. a=LpSolit.Gervase Markham2011-11-013-6/+6
* Bug 685552 - Email auto-completion causes server to thrashDavid Lawrence2011-10-242-2/+5
* Bug 680780: Advanced Search: help for field Comment is missing a spaceFrédéric Buclin2011-08-301-1/+1
* Bug 678844: When trying to edit a non-existent classification, the error mess...Frédéric Buclin2011-08-161-2/+4
* Bug 460074: Make post_bug.cgi use should_set for the group field, so itMax Kanat-Alexander2011-08-151-0/+1
* Bug 677187: If the attachment filename contains a newline, an error is thrown...Frédéric Buclin2011-08-101-2/+3
* Bug 637981: (CVE-2011-2379) [SECURITY] "Raw Unified" patch diffs can cause XS...Byron Jones2011-08-041-0/+5
* Bug 653477: (CVE-2011-2380) [SECURITY] Group names can be guessed when creati...Frédéric Buclin2011-08-041-20/+8
* Bug 657158 - (CVE-2011-2381) [SECURITY] Request email headers for attachment ...Reed Loden2011-08-041-1/+1
* Bug 676237: The traceback in code-error.html.tmpl is displayed on a single lineFrédéric Buclin2011-08-041-1/+1
* Bug 675754: Release notes for Bugzilla 4.0.2Frédéric Buclin2011-08-031-0/+42
* Bug 634812: Having a very large number of custom fields can make displaying s...Frédéric Buclin2011-08-014-25/+26
* Bug 673976: Style for #somebugs is duplicated in create-guided.html.tmplFrédéric Buclin2011-07-261-0/+2
* Bug 647158: The Error Console in Firefox reportsFrédéric Buclin2011-07-263-76/+46
* Bug 674089: Add a new hook 'end_object_name' in user-error.html.tmpl templateTiago Mello2011-07-251-0/+1
* Bug 674117: Add a new hook 'auth_failure_object' in user-error.html.tmpl temp...Tiago Mello2011-07-251-0/+2
* Bug 642388: Description of field days_elapsed missing from global/field-descs...Frédéric Buclin2011-07-251-0/+1
* Bug 670670 - New hook for requests.cgi that allows for additional links after...David Lawrence2011-07-221-1/+4
* Bug 669223: Add a new hook 'before_table' in list-classifications.html.tmpl t...Tiago Mello2011-07-201-0/+2
* Bug 652410 - 500+ consecutive lines of markup whitespace in show_bug.cgi flag...David Lawrence2011-07-061-6/+6
* Revert wrong indentation, see bug 652427Frédéric Buclin2011-07-011-1/+1
* Bug 652427: Going back to the new bug page loses the description if possible ...Guy Pyrzak2011-06-282-2/+3
* Bug 659124 - New template hook in bug/show-header.html.tmpl to allow manipula...David Lawrence2011-05-231-0/+2
* Bug 658056 - Improper HTML on show_bug.cgi page when user is logged outDavid Lawrence2011-05-181-7/+13
* Bug 653341: Bug.create() fails to error out if an invalid group is passedFrédéric Buclin2011-05-061-0/+7
* Bug 654833 - New hook to add additional attachment action links to the attach...David Lawrence2013-05-041-0/+1
* Bug 653406: fix escaping of url vars in error messagesByron Jones2011-04-291-8/+8