/[Apache-SVN]
ViewVC logotype

Revision 1349905


Jump to revision: Previous Next
Author: jorton
Date: Wed Jun 13 15:33:48 2012 UTC (11 years ago)
Changed paths: 2
Log Message:
SECURITY: CVE-2012-2687 (cve.mitre.org):

mod_negotiation: Escape filenames in variant list to prevent an
possible XSS for a site where untrusted users can upload files to a
location with MultiViews enabled.

* modules/mappers/mod_negotiation.c (make_variant_list): Escape
  filenames in variant list.

Submitted by: Niels Heinen <heinenn google.com>


Changed paths

Path Details
Directoryhttpd/httpd/trunk/CHANGES modified , text changed
Directoryhttpd/httpd/trunk/modules/mappers/mod_negotiation.c modified , text changed

infrastructure at apache.org
ViewVC Help
Powered by ViewVC 1.1.26