diff options
author | lpsolit%gmail.com <> | 2006-10-15 04:44:05 +0000 |
---|---|---|
committer | lpsolit%gmail.com <> | 2006-10-15 04:44:05 +0000 |
commit | 6fcfcb93eda16108f71b4c96010bae95cde622cd (patch) | |
tree | 330f34de1cf473325a7f1ce996099579bbfe7a90 /show_bug.cgi | |
parent | Bug 355728: [SECURITY] XSS in the "id" parameter of showdependencygraph.cgi w... (diff) | |
download | bugzilla-6fcfcb93eda16108f71b4c96010bae95cde622cd.tar.gz bugzilla-6fcfcb93eda16108f71b4c96010bae95cde622cd.tar.bz2 bugzilla-6fcfcb93eda16108f71b4c96010bae95cde622cd.zip |
Bug 346564: [SECURITY] timetracking deadline leaks in XML - Patch by Olav Vitters <bugzilla-mozilla@bkor.dhs.org> r=LpSolit a=justdave
Diffstat (limited to 'show_bug.cgi')
-rwxr-xr-x | show_bug.cgi | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/show_bug.cgi b/show_bug.cgi index 06a7b6425..37d31efe0 100755 --- a/show_bug.cgi +++ b/show_bug.cgi @@ -120,7 +120,7 @@ if ($cgi->param("field")) { } unless (Bugzilla->user->in_group(Bugzilla->params->{"timetrackinggroup"})) { - @fieldlist = grep($_ !~ /_time$/, @fieldlist); + @fieldlist = grep($_ !~ /(^deadline|_time)$/, @fieldlist); } foreach (@fieldlist) { |