1. 18 Nov, 2016 1 commit
  2. 16 Nov, 2016 3 commits
  3. 09 Nov, 2016 2 commits
    • DaVieS's avatar
      c47fc901
    • Jean Weisbuch's avatar
      Fix of a security and cosmetic bug on the SERVER_ADMIN server variable which... · 17aa3b9a
      Jean Weisbuch authored
      Fix of a security and cosmetic bug on the SERVER_ADMIN server variable which is not always set to the "ServerAdmin" value from the database :
        If the URL is matching a "vhs_ScriptAlias" or "vhs_Alias" directive, it sometimes returns the ServerAdmin value from database, sometimes returns the default "ServerAdmin" from httpd.conf and sometimes its leaking datas (on some cases it returned the last chars of the "AccessFileName" directive, on other cases a garbled string).
        The fix is not correcting the real issue (server->server_admin is somewhere set at a wrong value) but forces it to the value of the ServerAdmin column if set, else it falls back to webmaster@$hostname which is the "default" behavior of the vhs_translate_name() function if the URL is not matching an alias or a redirect
      17aa3b9a
  4. 08 Nov, 2016 1 commit
  5. 25 Apr, 2016 5 commits