[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-23 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 Chris Cormack changed: What|Removed |Added Assignee|ch...@bigballofwax.co.nz|koha-b...@lists.koha-commun

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-23 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 --- Comment #25 from Fridolin SOMERS --- There is a problem with some pages calling get_template_and_user with empty string in template_name : acqui/updatesupplier.pl opac/opac-ratings.pl tools/quotes/quotes_ajax.pl tools/quotes/quot

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-23 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 --- Comment #26 from Fridolin SOMERS --- also, minor error : dot must be espaced in regexp and I dont understand why there is a "?" at the end : ^[$safe_chars]+\.tt$ Do I create a new Bug ? -- You are receiving this mail because:

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-23 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 --- Comment #27 from Jonathan Druart --- (In reply to Fridolin SOMERS from comment #26) > also, minor error : > dot must be espaced in regexp and I dont understand why there is a "?" at > the end : > ^[$safe_chars]+\.tt$ > > Do I cr

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-23 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 --- Comment #28 from Fridolin SOMERS --- Pushed to 3.14.x, will be in 3.14.16 -- You are receiving this mail because: You are watching all bug changes. You are the assignee for the bug. __

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-23 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 --- Comment #29 from Jonathan Druart --- (In reply to Fridolin SOMERS from comment #25) > There is a problem with some pages calling get_template_and_user with empty > string in template_name : > > acqui/updatesupplier.pl > opac/opac

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-23 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 Fridolin SOMERS changed: What|Removed |Added Blocks||14439 -- You are receivin

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-23 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 --- Comment #30 from Jacek Ablewicz --- (In reply to Liz Rea from comment #24) > Pushed to 3.18.x will be in 3.18.08 Correction from the last patch in this set (Bug 14408: Allow integers in template paths) seems to be missing in 3.18

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-23 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 Jacek Ablewicz changed: What|Removed |Added CC||a...@biblos.pk.edu.pl -- Y

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-23 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 --- Comment #31 from Mason James --- Pushed to 3.16.x, will be in 3.16.12 -- You are receiving this mail because: You are the assignee for the bug. You are watching all bug changes. ___ Ko

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-23 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 Fridolin SOMERS changed: What|Removed |Added Blocks||14440 -- You are receivin

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-23 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 --- Comment #32 from Fridolin SOMERS --- I've created Bug 14439 and Bug 14440 -- You are receiving this mail because: You are watching all bug changes. You are the assignee for the bug. __

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-23 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 --- Comment #33 from Fridolin SOMERS --- (In reply to Mason James from comment #31) > Pushed to 3.16.x, will be in 3.16.12 Ok, the changes are different from 3.18.x and upper. I've reverted my patches in 3.14 to copy those from 3.16.

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-23 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 --- Comment #34 from Liz Rea --- Hi, I've created a patch for 3.18 that contains that last fix, but doesn't use the tests. It's pushed and rolled up to the download site. Liz -- You are receiving this mail because: You are watch

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-24 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 --- Comment #35 from Jacek Ablewicz --- Another side effect of this patches is that item search gets broken (3.18.x and up seems to be affected), because we have at least two templates like this: - catalogue/itemsearch.json.tt

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-24 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 --- Comment #36 from Liz Rea --- Hi Jacob, Please report this as a separate bug, you can mark it as a blocker for this one. Cheers, Liz -- You are receiving this mail because: You are watching all bug changes. You are the assign

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-24 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 --- Comment #37 from Liz Rea --- Jacek... I'm so sorry my contacts are getting sticky. Liz -- You are receiving this mail because: You are the assignee for the bug. You are watching all bug changes.

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-24 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 --- Comment #38 from Liz Rea --- Created attachment 40564 --> http://bugs.koha-community.org/bugzilla3/attachment.cgi?id=40564&action=edit bug 14408 - itemsearch no longer working To test: Click Advanced search in staff client Clic

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-24 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 Liz Rea changed: What|Removed |Added Status|Pushed to Stable|ASSIGNED -- You are receiving thi

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-24 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 Liz Rea changed: What|Removed |Added Status|ASSIGNED|Needs Signoff -- You are receivin

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-24 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 Liz Rea changed: What|Removed |Added Attachment #40564|0 |1 is obsolete|

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-24 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 Chris Cormack changed: What|Removed |Added Status|Needs Signoff |Signed Off C

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-24 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 Chris Cormack changed: What|Removed |Added Status|Signed Off |Passed QA -- You are receiv

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-24 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 Chris Cormack changed: What|Removed |Added Status|Passed QA |Pushed to Stable -- You are

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-24 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 Liz Rea changed: What|Removed |Added Depends on||14450 -- You are receiving this m

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-24 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 Jonathan Druart changed: What|Removed |Added Blocks||14450 Depends on|1

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-06-24 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 --- Comment #39 from Liz Rea --- Created attachment 40610 --> http://bugs.koha-community.org/bugzilla3/attachment.cgi?id=40610&action=edit Bug 14408 & 14439 - typo fixes for regexes As applied to 3.18.8 - still need tests for these

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-07-02 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 Jacek Ablewicz changed: What|Removed |Added Blocks||14467 -- You are receiving

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-07-24 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 --- Comment #40 from Mason James --- Pushed to 3.16.x, will be in 3.16.13 -- You are receiving this mail because: You are the assignee for the bug. You are watching all bug changes. ___ Ko

[Koha-bugs] [Bug 14408] Path traversal vulnerabilty

2015-07-24 Thread bugzilla-daemon
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14408 --- Comment #41 from Mason James --- (In reply to Mason James from comment #40) > Pushed to 3.16.x, will be in 3.16.13 oops, was actually included in 3.16.12 release -- You are receiving this mail because: You are the assignee for