MantisBT: master 38325e28

Author Committer Branch Timestamp Parent
dregad dregad master 2014-12-29 14:12 master b5eb9305
Affected Issues  0012908: PHP remote code execution in install.php
 0017012: Quotes not escaped on install
Changeset

Install: escape strings inserted in config_inc.php

This ensures it is not possible to inject arbitrary PHP code into the
generated config file.

Fixes 0012908, 0017012

mod - admin/install.php Diff File