MantisBT: master-1.2.x 965b00a0

Author Committer Branch Timestamp Parent
dhx dhx master-1.2.x 2011-09-03 15:34 master-1.2.x a7eacc18
Affected Issues  0013282: bug_actiongroup_ext_page.php does not properly sanitise action parameter before including local files
 0013283: bug_actiongroup_ext_page.php remote file inclusion: action parameter
Changeset

Revert "Fix 0013282, 0013283: bug_actiongroup_ext_page.php LFI and XSS"

This reverts commit a7eacc181185eff1dd7bd8ceaa34a91cf86cc298.

Paul fixed this in a better way with commit
a908cc61362059025910e2437d55bedc31863139 (to be backported to 1.2.x
after this older commit is reverted).

mod - bug_actiongroup_ext_page.php Diff File
mod - core/bug_group_action_api.php Diff File