[Koha-devel] Possible OPAC security pb

Galen Charlton gmc at esilibrary.com
Mon Jul 15 17:22:09 CEST 2013


Hi,

On Mon, Jul 15, 2013 at 7:20 AM, Robin Sheat <robin at catalyst.net.nz> wrote:

> This said, there are two patches there now: Fridolyn's one that filters
> on input, and my followup that parameterises the SQL to add another
> layer of defence (also doing queries the way they're supposed to be
> done.)
>

These two patches have now been tested and pushed to master [1, 2]

[1]
http://git.koha-community.org/gitweb/?p=koha.git;a=commit;h=57866d6b67c3f8b29290150f21c71395315a73fe
[2]
http://git.koha-community.org/gitweb/?p=koha.git;a=commit;h=89cf013a6fadcb1347151798f3fdab0d8c75cd15

Regards,

Galen
-- 
Galen Charlton
Manager of Implementation
Equinox Software, Inc. / The Open Source Experts
email:  gmc at esilibrary.com
direct: +1 770-709-5581
cell:   +1 404-984-4366
skype:  gmcharlt
web:    http://www.esilibrary.com/
Supporting Koha and Evergreen: http://koha-community.org &
http://evergreen-ils.org
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.koha-community.org/pipermail/koha-devel/attachments/20130715/e6596da3/attachment.html>


More information about the Koha-devel mailing list