cacert-devel.git
4 years agoMerge remote-tracking branch 'origin/bug-1318' into release
Michael Tänzer [Fri, 5 Dec 2014 00:11:53 +0000 (01:11 +0100)] 
Merge remote-tracking branch 'origin/bug-1318' into release

4 years agoMerge remote-tracking branch 'origin/bug-1288' into release
Michael Tänzer [Thu, 4 Dec 2014 21:50:46 +0000 (22:50 +0100)] 
Merge remote-tracking branch 'origin/bug-1288' into release

4 years agoMerge branch 'tarballs' into release
Michael Tänzer [Thu, 4 Dec 2014 18:08:25 +0000 (19:08 +0100)] 
Merge branch 'tarballs' into release

Conflicts:
scripts/send_policy_cca_20140916.php

Signed-off-by: Michael Tänzer <neo@nhng.de>
4 years agoSource code taken from cacert-20141124.tar.bz2
Michael Tänzer [Thu, 4 Dec 2014 17:26:23 +0000 (18:26 +0100)] 
Source code taken from cacert-20141124.tar.bz2

4 years agobug 1318: Minor typo bug-1318
Benny Baumann [Sun, 30 Nov 2014 18:03:44 +0000 (19:03 +0100)] 
bug 1318: Minor typo

4 years agobug 1318: Variable name typo
Benny Baumann [Sun, 30 Nov 2014 17:57:09 +0000 (18:57 +0100)] 
bug 1318: Variable name typo

4 years agobug 1288: Some cleanup as this is never used anyway bug-1288
Benny Baumann [Sun, 30 Nov 2014 17:42:09 +0000 (18:42 +0100)] 
bug 1288: Some cleanup as this is never used anyway

4 years agobug 1288: Accept STARTTLS as last option
Benny Baumann [Sun, 30 Nov 2014 00:31:25 +0000 (01:31 +0100)] 
bug 1288: Accept STARTTLS as last option

4 years agobug 1318: typo in variable names
Benny Baumann [Sat, 29 Nov 2014 14:11:15 +0000 (15:11 +0100)] 
bug 1318: typo in variable names

4 years agobug 1318: Actually sort by priority
Benny Baumann [Sat, 29 Nov 2014 14:08:09 +0000 (15:08 +0100)] 
bug 1318: Actually sort by priority

4 years agobug 1318: Fix a check for if there were any servers
Benny Baumann [Sat, 29 Nov 2014 13:58:20 +0000 (14:58 +0100)] 
bug 1318: Fix a check for if there were any servers

4 years agobug 1318: Request the array containing the priorities to sort entries propoerly
Benny Baumann [Sat, 29 Nov 2014 13:50:31 +0000 (14:50 +0100)] 
bug 1318: Request the array containing the priorities to sort entries propoerly

4 years agobug 1288: Actually request encryption for the connection before activating
Benny Baumann [Sat, 29 Nov 2014 13:44:09 +0000 (14:44 +0100)] 
bug 1288: Actually request encryption for the connection before activating

4 years agobug 1288: EHLO returns 250 on success
Benny Baumann [Sat, 29 Nov 2014 13:33:18 +0000 (14:33 +0100)] 
bug 1288: EHLO returns 250 on success

4 years agobug 1318: Typo in control structure
Benny Baumann [Sat, 29 Nov 2014 13:26:16 +0000 (14:26 +0100)] 
bug 1318: Typo in control structure

4 years agobug 1288: Do STARTTLS whenever offered by the server
Benny Baumann [Sat, 29 Nov 2014 12:48:19 +0000 (13:48 +0100)] 
bug 1288: Do STARTTLS whenever offered by the server

4 years agobug 1318: Properly order MX records by order given in RFC 5321
Benny Baumann [Sat, 29 Nov 2014 12:46:50 +0000 (13:46 +0100)] 
bug 1318: Properly order MX records by order given in RFC 5321

4 years agoMerge branch 'bug-28' into release
Benny Baumann [Sun, 23 Nov 2014 14:21:16 +0000 (15:21 +0100)] 
Merge branch 'bug-28' into release

Conflicts:
includes/account.php
scripts/cron/warning.php
www/disputes.php
www/wot.php

4 years agoMerge branch 'bug-1273' into release
Benny Baumann [Sun, 23 Nov 2014 14:02:56 +0000 (15:02 +0100)] 
Merge branch 'bug-1273' into release

4 years agoMerge branch 'bug-1192' into release
Benny Baumann [Sun, 23 Nov 2014 14:02:16 +0000 (15:02 +0100)] 
Merge branch 'bug-1192' into release

4 years agoMerge branch 'bug-1339' into release
Benny Baumann [Tue, 18 Nov 2014 18:36:13 +0000 (19:36 +0100)] 
Merge branch 'bug-1339' into release

4 years agobug-1339: remove all traces of OTP bug-1339
Felix Dörre [Sat, 15 Nov 2014 11:12:12 +0000 (12:12 +0100)] 
bug-1339: remove all traces of OTP

5 years agobug-1273: fixing backticks in 'warning'-cron-script bug-1273
Felix Dörre [Tue, 21 Oct 2014 20:38:35 +0000 (22:38 +0200)] 
bug-1273: fixing backticks in 'warning'-cron-script

5 years agoMerge remote-tracking branch 'origin/bug-1301' into release
Michael Tänzer [Thu, 16 Oct 2014 19:00:38 +0000 (21:00 +0200)] 
Merge remote-tracking branch 'origin/bug-1301' into release

5 years agobug-1192: changed text on index/52.php bug-1192
INOPIAE [Tue, 14 Oct 2014 19:59:57 +0000 (21:59 +0200)] 
bug-1192: changed text on index/52.php

5 years agobug-1192: added explanation text
INOPIAE [Tue, 30 Sep 2014 20:00:07 +0000 (22:00 +0200)] 
bug-1192: added explanation text

5 years agoCCA-Mailing: bugfix for script continuation problem reported by Wytze
Benny Baumann [Wed, 24 Sep 2014 19:43:32 +0000 (21:43 +0200)] 
CCA-Mailing: bugfix for script continuation problem reported by Wytze

5 years agoadd: Policy Mailing script for notification about the new CCA as of 2014-07-20.
Benny Baumann [Tue, 16 Sep 2014 07:31:53 +0000 (09:31 +0200)] 
add: Policy Mailing script for notification about the new CCA as of 2014-07-20.

5 years agobug 1301: Fix issue with missing default for the encoding bug-1301
Benny Baumann [Fri, 29 Aug 2014 22:53:41 +0000 (00:53 +0200)] 
bug 1301: Fix issue with missing default for the encoding

5 years agoMerge branch 'bug-1293' into release
Benny Baumann [Thu, 28 Aug 2014 07:22:31 +0000 (09:22 +0200)] 
Merge branch 'bug-1293' into release

5 years agoMerge branch 'bug-1297' into release
Benny Baumann [Wed, 20 Aug 2014 20:34:25 +0000 (22:34 +0200)] 
Merge branch 'bug-1297' into release

5 years agoMerge branch 'bug-1298' into release
Benny Baumann [Wed, 20 Aug 2014 20:34:10 +0000 (22:34 +0200)] 
Merge branch 'bug-1298' into release

5 years agoMerge branch 'bug-1292' into release
Benny Baumann [Wed, 20 Aug 2014 20:30:21 +0000 (22:30 +0200)] 
Merge branch 'bug-1292' into release

5 years agoMerge branch 'bug-1276' into release
Benny Baumann [Wed, 20 Aug 2014 20:29:44 +0000 (22:29 +0200)] 
Merge branch 'bug-1276' into release

5 years agobug 1293: Additional changes to CCA by Benedikt bug-1293
Benny Baumann [Tue, 19 Aug 2014 20:48:03 +0000 (22:48 +0200)] 
bug 1293: Additional changes to CCA by Benedikt

5 years agobug 1293: Updated latest CCA version by Benedikt 2014-08-19 20:56
Benny Baumann [Tue, 19 Aug 2014 20:09:35 +0000 (22:09 +0200)] 
bug 1293: Updated latest CCA version by Benedikt 2014-08-19 20:56

5 years agobug 1293: Renewed version provided by the Editor
Benny Baumann [Mon, 18 Aug 2014 05:18:19 +0000 (07:18 +0200)] 
bug 1293: Renewed version provided by the Editor

5 years agoUpdated Policy document by the Editor
Benny Baumann [Sun, 17 Aug 2014 21:47:37 +0000 (23:47 +0200)] 
Updated Policy document by the Editor

5 years agobug 1293: Remove the icon according to W3C guidelines
Benny Baumann [Sun, 17 Aug 2014 15:33:33 +0000 (17:33 +0200)] 
bug 1293: Remove the icon according to W3C guidelines

This change is as we currently do not pass validation and
therefore would be infridging on the usage rights.

5 years agobug 1293: Replace DOCTYPE by HTML5 declaration to avoid conflicts with PHP and the...
Benny Baumann [Wed, 13 Aug 2014 22:10:03 +0000 (00:10 +0200)] 
bug 1293: Replace DOCTYPE by HTML5 declaration to avoid conflicts with PHP and the XML declaration for XHTML 1.1

5 years agoMerge branch 'bug-1291' into release
Benny Baumann [Sat, 9 Aug 2014 08:56:14 +0000 (10:56 +0200)] 
Merge branch 'bug-1291' into release

5 years agobug-1298: Update the used SHA-import in the commmodule bug-1298
Felix Dörre [Fri, 8 Aug 2014 23:31:43 +0000 (01:31 +0200)] 
bug-1298: Update the used SHA-import in the commmodule

As already suggested in the bug report.

5 years agobug-1297: update openssl regexes to openssl 1.0.1 bug-1297
Felix Dörre [Fri, 8 Aug 2014 23:27:10 +0000 (01:27 +0200)] 
bug-1297: update openssl regexes to openssl 1.0.1

Some keywords in the "req"-output have changed.

5 years agobug 1291: Update wothash calculation for modified behaviour bug-1291
Benny Baumann [Tue, 29 Jul 2014 21:29:14 +0000 (23:29 +0200)] 
bug 1291: Update wothash calculation for modified behaviour

5 years agobug 1293: Add new DRAFT version of current CCA as of 2014-ß7-27
Benny Baumann [Tue, 29 Jul 2014 21:09:50 +0000 (23:09 +0200)] 
bug 1293: Add new DRAFT version of current CCA as of 2014-ß7-27

5 years agobug 1291: Another XSS
Benny Baumann [Sun, 27 Jul 2014 14:25:24 +0000 (16:25 +0200)] 
bug 1291: Another XSS

5 years agobug 1291: Fix XSS in WoT 15
Felix Dörre [Sun, 27 Jul 2014 10:49:28 +0000 (12:49 +0200)] 
bug 1291: Fix XSS in WoT 15

5 years agobug-1292: prohibit keys with public exponent smaller than 65536 bug-1292
Felix Dörre [Sat, 26 Jul 2014 22:54:34 +0000 (00:54 +0200)] 
bug-1292: prohibit keys with public exponent smaller than 65536

This is in accordance to what is recommended on the referenced
wiki page: http://wiki.cacert.org/WeakKeys#SmallExponent

5 years agoMerge branch 'bug-1226' into release
Benny Baumann [Tue, 15 Jul 2014 18:26:08 +0000 (20:26 +0200)] 
Merge branch 'bug-1226' into release

5 years agoMerge branch 'bug-1283' into release
Benny Baumann [Tue, 15 Jul 2014 18:25:46 +0000 (20:25 +0200)] 
Merge branch 'bug-1283' into release

5 years agoMerge branch 'bug-1281' into release
Benny Baumann [Tue, 15 Jul 2014 18:25:29 +0000 (20:25 +0200)] 
Merge branch 'bug-1281' into release

5 years agoMerge branch 'bug-1280' into release
Benny Baumann [Tue, 15 Jul 2014 18:24:39 +0000 (20:24 +0200)] 
Merge branch 'bug-1280' into release

5 years agobug 1226: Only consider values above 1900 as the year when returning a pre-filled... bug-1226
Benny Baumann [Sat, 21 Jun 2014 22:45:15 +0000 (00:45 +0200)] 
bug 1226: Only consider values above 1900 as the year when returning a pre-filled form

5 years agobug 1226: Properly use sprintf
Michael Tänzer [Sat, 21 Jun 2014 21:58:45 +0000 (23:58 +0200)] 
bug 1226: Properly use sprintf

Signed-off-by: Michael Tänzer <neo@nhng.de>
5 years agobug 1226: Treat the date values as integer
Michael Tänzer [Sat, 21 Jun 2014 21:56:28 +0000 (23:56 +0200)] 
bug 1226: Treat the date values as integer

Signed-off-by: Michael Tänzer <neo@nhng.de>
5 years agobug 1226: Remove really redundant code
Michael Tänzer [Sat, 21 Jun 2014 21:55:43 +0000 (23:55 +0200)] 
bug 1226: Remove really redundant code

Signed-off-by: Michael Tänzer <neo@nhng.de>
5 years agobug 1280: Implement normalisation in of language codes in the L10n class bug-1280
Michael Tänzer [Sat, 21 Jun 2014 17:15:48 +0000 (19:15 +0200)] 
bug 1280: Implement normalisation in of language codes in the L10n class
and use it (in set_translation() and the Assurer contact form)

Signed-off-by: Michael Tänzer <neo@nhng.de>
5 years agobug 1280: Remove trailing white space
Michael Tänzer [Sat, 21 Jun 2014 17:03:39 +0000 (19:03 +0200)] 
bug 1280: Remove trailing white space

Signed-off-by: Michael Tänzer <neo@nhng.de>
5 years agoRevert "bug-1280: Parse the language code from the locale."
Michael Tänzer [Sat, 21 Jun 2014 15:37:54 +0000 (17:37 +0200)] 
Revert "bug-1280: Parse the language code from the locale."

This reverts commit f3885b3bc9ff61da78fb541151f16b0ecfdf62eb.

5 years agoRevert "bug-1280: Handle more different types of "languages":"
Michael Tänzer [Sat, 21 Jun 2014 15:37:53 +0000 (17:37 +0200)] 
Revert "bug-1280: Handle more different types of "languages":"

This reverts commit 0730c9df3eb440205d7963e3c0762765d9b47031.

5 years agoRevert "bug-1280: Variable naming, formatting, php-syntax-error"
Michael Tänzer [Sat, 21 Jun 2014 15:37:44 +0000 (17:37 +0200)] 
Revert "bug-1280: Variable naming, formatting, php-syntax-error"

This reverts commit 6b1cd2a57b0aaa88374b1098df40cc6f73cdff5d.

5 years agobug 1273: Move the one "escapeshellarg" in a new row.
Felix Dörre [Sun, 15 Jun 2014 13:00:41 +0000 (15:00 +0200)] 
bug 1273: Move the one "escapeshellarg" in a new row.

5 years agobug 1273: use runCommand where former "echo"-syntax was used
Felix Dörre [Sun, 15 Jun 2014 09:48:10 +0000 (11:48 +0200)] 
bug 1273: use runCommand where former "echo"-syntax was used

5 years agobug 1273: replace backtick operators with shell_exec
Felix Dörre [Sun, 15 Jun 2014 08:39:04 +0000 (10:39 +0200)] 
bug 1273: replace backtick operators with shell_exec

+ fix 1 missing escapeshellarg
Commands used to locate:
1.
find includes -type f -name '*.php' -exec cat {} \; \
| tr '\n' '?' | sed 's/\(\$query .\?= \|\
mysql_query(\|query_init (\)"\([^"]\|".\(\(intval\|mysql_real_escape_string\)\
(\$[^\$)]\+)\|\$_SESSION\(\['_config'\]\['user'\]\['Q[1-5]'\]\
\|['_config']['disablelogin']\)\)[ ?]*."\)*"/mysql-substitute/g'\
| tr '?' '\n' |  grep --color=always "\`"|less -r

and reviewing the queries by hand.

This command replaces out strings obviously looking
like sql_queries and then outputting al remaining backticks:

starting with "$query = ,mysql_query, ..."
and are only interrupted by "safe" calls:
- mysql_real_escape_string
- intval
- pre_escaped session variables

(This command may also be used for locating
 bad escaped sql_queries)

2. grep -r "\`\(grep\|/\|echo\|dig\|openssl\|gpg\|rm\|../\)" www includes pages \
| grep -v '\(from\|update\|into\) `gpg'

5 years agoMerge branch 'bug-807' into release
Benny Baumann [Fri, 13 Jun 2014 07:20:43 +0000 (09:20 +0200)] 
Merge branch 'bug-807' into release

5 years agoMerge branch 'release' into bug-807
Benny Baumann [Fri, 13 Jun 2014 07:19:57 +0000 (09:19 +0200)] 
Merge branch 'release' into bug-807

Conflicts:
includes/account.php
includes/lib/account.php
pages/account/16.php

5 years agobug-1280: Variable naming, formatting, php-syntax-error
Felix Dörre [Wed, 11 Jun 2014 17:49:42 +0000 (19:49 +0200)] 
bug-1280: Variable naming, formatting, php-syntax-error

5 years agobug-1280: Handle more different types of "languages":
Felix Dörre [Wed, 11 Jun 2014 15:04:12 +0000 (17:04 +0200)] 
bug-1280: Handle more different types of "languages":

- zh_CN => zh-cn (in various cases: ZH_cn, zh_cn, ...)
- de => de (what the current GUI produces)
- de_DE => de, en_AU => en, EN_AU => en  (what may be left in the database)
... and more creative upper/lower-cases

5 years agobug-1280: Parse the language code from the locale.
Felix Dörre [Tue, 10 Jun 2014 22:20:43 +0000 (00:20 +0200)] 
bug-1280: Parse the language code from the locale.

Splitting the string at "_" and lowering the characters.

5 years agobug 1283: remove double encoding bug-1283
Felix Dörre [Tue, 10 Jun 2014 21:36:17 +0000 (23:36 +0200)] 
bug 1283: remove double encoding

The locales are already encoded in the Database.

5 years agobug 1281: Fix syntax error in SQL statement bug-1281
Benny Baumann [Sun, 8 Jun 2014 20:10:19 +0000 (22:10 +0200)] 
bug 1281: Fix syntax error in SQL statement

5 years agobug 1281: Convert to Unix Line Endings
Benny Baumann [Sun, 8 Jun 2014 19:54:12 +0000 (21:54 +0200)] 
bug 1281: Convert to Unix Line Endings

5 years agoMerge branch 'bug-929' into release
Benny Baumann [Sat, 7 Jun 2014 08:07:53 +0000 (10:07 +0200)] 
Merge branch 'bug-929' into release

5 years agoMerge branch 'bug-1172' into release
Benny Baumann [Fri, 6 Jun 2014 21:50:49 +0000 (23:50 +0200)] 
Merge branch 'bug-1172' into release

5 years agoMerge branch 'bug-1138' into release
Benny Baumann [Fri, 6 Jun 2014 20:58:42 +0000 (22:58 +0200)] 
Merge branch 'bug-1138' into release

5 years agoMerge branch 'bug-1275' into release
Benny Baumann [Fri, 6 Jun 2014 17:55:39 +0000 (19:55 +0200)] 
Merge branch 'bug-1275' into release

5 years agoMerge branch 'bug-372' into release
Benny Baumann [Fri, 6 Jun 2014 17:54:51 +0000 (19:54 +0200)] 
Merge branch 'bug-372' into release

5 years agoMerge branch 'bug-413' into bug-1138 bug-1138
Benny Baumann [Fri, 6 Jun 2014 16:58:04 +0000 (18:58 +0200)] 
Merge branch 'bug-413' into bug-1138

Conflicts:
pages/account/12.php
pages/account/5.php

5 years agobug 413: Port same change as for 5.php over to 12.php bug-413
Benny Baumann [Tue, 27 May 2014 21:12:43 +0000 (23:12 +0200)] 
bug 413: Port same change as for 5.php over to 12.php

5 years agobug 413: Backport changes from 7aced740 by Michael Tänzer to avoid conflicts when...
Benny Baumann [Tue, 27 May 2014 20:56:58 +0000 (22:56 +0200)] 
bug 413: Backport changes from 7aced740 by Michael Tänzer to avoid conflicts when integrating both together

5 years agobug 1138: that "if" should contain a block
Michael Tänzer [Mon, 26 May 2014 22:09:12 +0000 (00:09 +0200)] 
bug 1138: that "if" should contain a block

goto fail;

Signed-off-by: Michael Tänzer <neo@nhng.de>
5 years agobug 1138: fix double-escaping in wot/10
Benny Baumann [Tue, 20 May 2014 20:46:26 +0000 (22:46 +0200)] 
bug 1138: fix double-escaping in wot/10

5 years agobug 1276: Allow more name variants according to PracticeOnNames when signing a PGP key bug-1276
Alex English [Sun, 11 May 2014 17:24:34 +0000 (19:24 +0200)] 
bug 1276: Allow more name variants according to PracticeOnNames when signing a PGP key

Signed-off-by: Benny Baumann <BenBE@geshi.org>
5 years agobug 1138: $verified is a string that is directly filled with data from the
Michael Tänzer [Wed, 30 Apr 2014 23:54:51 +0000 (01:54 +0200)] 
bug 1138: $verified is a string that is directly filled with data from the
translation system => do not intval()

Signed-off-by: Michael Tänzer <neo@nhng.de>
5 years agobug 1138: This is an int, no need to mysql_real_escape()
Michael Tänzer [Wed, 30 Apr 2014 23:31:19 +0000 (01:31 +0200)] 
bug 1138: This is an int, no need to mysql_real_escape()

Signed-off-by: Michael Tänzer <neo@nhng.de>
5 years agobug 1138: Avoid double escaping of $_SESSION['_config']['OU'] and fix XSS
Michael Tänzer [Wed, 30 Apr 2014 23:05:17 +0000 (01:05 +0200)] 
bug 1138: Avoid double escaping of $_SESSION['_config']['OU'] and fix XSS

Signed-off-by: Michael Tänzer <neo@nhng.de>
5 years agobug 1138: Avoid double escaping.
Michael Tänzer [Wed, 30 Apr 2014 21:47:33 +0000 (23:47 +0200)] 
bug 1138: Avoid double escaping.

These session variables should be local variables as they aren't needed
anywhere else

Signed-off-by: Michael Tänzer <neo@nhng.de>
5 years agobug 1138: Avoid double escaping in `description` which was stored into the
Michael Tänzer [Wed, 30 Apr 2014 21:36:56 +0000 (23:36 +0200)] 
bug 1138: Avoid double escaping in `description` which was stored into the
session mysql_real_escaped

Signed-off-by: Michael Tänzer <neo@nhng.de>
5 years agobug 1138: Avoid double escaping
Michael Tänzer [Wed, 30 Apr 2014 21:29:24 +0000 (23:29 +0200)] 
bug 1138: Avoid double escaping

Yes it's ugly but should be fixed in a separate bug

Signed-off-by: Michael Tänzer <neo@nhng.de>
5 years agoMerge branch 'release' into bug-1138
Benny Baumann [Wed, 30 Apr 2014 22:17:08 +0000 (00:17 +0200)] 
Merge branch 'release' into bug-1138

5 years agobug 1138: additional brackets for better readability
Benny Baumann [Tue, 29 Apr 2014 21:26:27 +0000 (23:26 +0200)] 
bug 1138: additional brackets for better readability

5 years agobug 1138: Reorder fields to better show which variables belong together
Benny Baumann [Tue, 29 Apr 2014 20:55:02 +0000 (22:55 +0200)] 
bug 1138: Reorder fields to better show which variables belong together

5 years agobug 1138: Whitespace changes and code formatting
Benny Baumann [Wed, 30 Apr 2014 16:30:20 +0000 (18:30 +0200)] 
bug 1138: Whitespace changes and code formatting

5 years agobug 1138: And yet another bunch of escaping
Benny Baumann [Wed, 30 Apr 2014 18:13:28 +0000 (20:13 +0200)] 
bug 1138: And yet another bunch of escaping

5 years agobug 1138: Some escaping for the GnuPG code
Benny Baumann [Wed, 30 Apr 2014 16:44:40 +0000 (18:44 +0200)] 
bug 1138: Some escaping for the GnuPG code

5 years agobug 1138: And yet another bunch of missing escapes
Benny Baumann [Wed, 30 Apr 2014 16:27:23 +0000 (18:27 +0200)] 
bug 1138: And yet another bunch of missing escapes

5 years agobug 1138: And yet some more sanitizing of database query arguments
Benny Baumann [Wed, 30 Apr 2014 15:24:21 +0000 (17:24 +0200)] 
bug 1138: And yet some more sanitizing of database query arguments

5 years agobug 1138: Add some more mising escaping for values from the database
Benny Baumann [Tue, 29 Apr 2014 23:14:53 +0000 (01:14 +0200)] 
bug 1138: Add some more mising escaping for values from the database

5 years agobug 1138: Add some more mising escaping for values from the database
Benny Baumann [Tue, 29 Apr 2014 22:56:23 +0000 (00:56 +0200)] 
bug 1138: Add some more mising escaping for values from the database

5 years agobug 1138: Add some mising escaping for values from the database
Benny Baumann [Tue, 29 Apr 2014 22:48:42 +0000 (00:48 +0200)] 
bug 1138: Add some mising escaping for values from the database