summaryrefslogtreecommitdiffstats
path: root/editusers.cgi
diff options
context:
space:
mode:
authorjustdave%syndicomm.com <>2003-11-03 12:31:30 +0100
committerjustdave%syndicomm.com <>2003-11-03 12:31:30 +0100
commita4e75a434f1fbbae4b438927ae02958baad7f1b7 (patch)
tree74a5ab12bbf20c934af898475a3f6c7303b68013 /editusers.cgi
parenta30e5f2cf9b04a8a377186ecb3b90b4311d23894 (diff)
downloadbugzilla-a4e75a434f1fbbae4b438927ae02958baad7f1b7.tar.gz
bugzilla-a4e75a434f1fbbae4b438927ae02958baad7f1b7.tar.xz
[SECURITY] Bug 219044: A user with 'editkeywords' privileges (i.e. usually an administrator) can inject arbitrary SQL via the URL used to edit an existing keyword.
Patch by Joel Peshkin <bugreport@peshkin.net> r= justdave, zach a= justdave
Diffstat (limited to 'editusers.cgi')
0 files changed, 0 insertions, 0 deletions