[AppDB] security fix for editAppVersion

Paul van Schayck polleke at gmail.com
Thu Jan 6 09:48:21 CST 2005


Hey Tony,

I'm afraid this patch is not entirely correct. We're now doing a
second addslashes() and we're not checking versiondId and appId.

Attached is a hopefully correct patch. Would be best to apply this ASAP.

Paul

Changelog:
Security fixes. Use include/db.php
-------------- next part --------------
A non-text attachment was scrubbed...
Name: appversion.diff
Type: text/x-patch
Size: 5781 bytes
Desc: not available
Url : http://www.winehq.org/pipermail/wine-patches/attachments/20050106/cfdc14e8/appversion.bin


More information about the wine-patches mailing list