Skip to content
Snippets Groups Projects
  1. Mar 16, 2010
    • Michael Hamann's avatar
      Use md5sum of id and client ip as temporary filename in XML-RPC · c77fa67b
      Michael Hamann authored
      Before this patch the temporary filename was the uncleaned id. This
      allowed everyone with upload-privileges (on the whole wiki) and XML-RPC
      privileges on a XML-RPC-enabled DokuWiki to (over)write any file PHP is
      allowed to write with any content he wants. If you have XML-RPC enabled
      and users with XML-RPC and upload privileges you don't trust in a way
      you would allow them to write any file PHP may write, consider this as
      an important security fix. By default XML-RPC is disabled, so if you
      don't know what I'm talking about you are probably not affected by the
      problem.
      c77fa67b
    • Christopher Smith's avatar
      Make constants in TarLib.class.php class constants · e0415e22
      Christopher Smith authored
      The constants are required by the class constructor, which effectively
      means before the autoloader is triggered.  This change fixes that issue.
      e0415e22
  2. Mar 15, 2010
    • Adrian Lang's avatar
      Various JavaScript fixes · fda42deb
      Adrian Lang authored
        * Syntax error fixed
        * lock refresh event is now attached to the whole edit form since it bubbles
          up and we cannot be sure that the wikitext input exists on all edit forms
        * Updated findPos(X|Y)
        * Easier and less error-prone way of getting the section edit button in the
          highlight mouseover event handler
      fda42deb
  3. Mar 12, 2010
  4. Mar 10, 2010
  5. Mar 09, 2010
  6. Mar 08, 2010
  7. Mar 03, 2010
  8. Mar 02, 2010
  9. Feb 28, 2010
  10. Feb 24, 2010
  11. Feb 23, 2010
  12. Feb 22, 2010
  13. Feb 15, 2010
  14. Feb 14, 2010
  15. Feb 12, 2010
  16. Feb 11, 2010
  17. Feb 10, 2010
Loading