aboutsummaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Bumped version to 4.0.5release-4.0.5bugzilla-4.0.5Dave Lawrence2012-02-222-3/+3
* Bug 725663 - (CVE-2012-0453) [SECURITY] CSRF vulnerability in the XML-RPC API...Dave Lawrence2012-02-223-0/+21
* Bug 727893: Release notes for Bugzilla 4.0.5Frédéric Buclin2012-02-171-0/+16
* Test 1 fails if PERLLIB contains paths with whitespace.Marc Schumann2012-02-151-1/+1
* Bug 727240: The POD for Bug.attachments is wrong about the format of the retu...Frédéric Buclin2012-02-141-16/+10
* Bug 722161: Clickjacking is possible in "View All" with HTML attachmentsFrédéric Buclin2012-02-082-4/+21
* Bump the version number post-releaseDave Lawrence2012-01-311-1/+1
* Bumped to correct daterelease-4.0.4bugzilla-4.0.4Dave Lawrence2012-01-311-1/+1
* Bumped to version 4.0.4Dave Lawrence2012-01-312-3/+3
* Bug 718319: (CVE-2012-0440) [SECURITY] JSON-RPC permits to bypass token check...Frédéric Buclin2012-01-313-0/+25
* Bug 714472: (CVE-2012-0448) [SECURITY] utf8 homoglyphs are allowed in email a...Frédéric Buclin2012-01-314-7/+5
* Bug 720752 - Release notes for Bugzilla 4.0.4Dave Lawrence2012-01-271-10/+35
* Bug 469068: SMTP parameters not documentedMatt Selsky2012-01-211-0/+62
* Bug 715733 - When deleting a user account, related data in the profile_search...Dave Lawrence2012-01-121-0/+3
* Bug 591638: In the admin page, the link to edit field values is named 'Field ...A. Shimono2012-01-111-1/+1
* Bug 715650 - User auto-completion does not work in request.cgi for requester ...Dave Lawrence2012-01-111-1/+2
* Bug 716283: Clickjacking in the attachment "Details" page allows to bypass to...Frédéric Buclin2012-01-102-4/+19
* Bug 319684: The documentation is unclear about how to disable quipsMatt Selsky2012-01-061-7/+12
* Bug 641957: The documentation should mention that the voting system is now an...Matt Selsky2012-01-061-0/+5
* Bug 715705: User auto-completion doesn't work for watched users in the email ...Frédéric Buclin2012-01-061-1/+2
* Bug 714664: The content of the "emailregexpdesc" parameter is not escaped whe...Frédéric Buclin2012-01-062-2/+2
* Bug 706753: Bugzilla will not work with newest version of JSON::RPC 1.01 due ...Frédéric Buclin2012-01-051-1/+12
* Bump the version number post-releaseDave Lawrence2011-12-291-1/+1
* Bump version for 4.0.3release-4.0.3bugzilla-4.0.3Dave Lawrence2011-12-282-3/+3
* Bug 711714: (CVE-2011-3667) [SECURITY] The User.offer_account_by_email WebSer...Frédéric Buclin2011-12-285-45/+51
* Bug 697699 - (CVE-2011-3657) [SECURITY] XSS when viewing new charts or tabula...Byron Jones2011-12-282-3/+3
* Bug 713345: Release notes for Bugzilla 4.0.3Frédéric Buclin2011-12-281-1/+53
* Bug 707428: Custom field values whose visibility depends on another field val...Frédéric Buclin2011-12-151-1/+1
* Bug 644281: When the sort order of a buglist is modified, the "Show next bug ...Frédéric Buclin2011-12-092-31/+25
* Bug 707170: Several features about custom fields are missing in the documenta...Frédéric Buclin2011-12-081-7/+50
* Bug 657290: Bug.add_attachment() stores truncated timestamps in the DB (secon...Frédéric Buclin2011-12-061-1/+4
* Bug 550299: User fields are left blank in buglists and whines when local user...Frédéric Buclin2011-12-064-38/+27
* Bug 692354: Incorrect parameter type in WebServices documentation for Bug.add...Matt Selsky2011-12-051-1/+1
* Bug 707594: Fix broken account lockout notificationsByron Jones2011-12-061-1/+2
* Bug 701350: Oracle crashes if the 'maxattachmentsize' parameter is set to a t...Frédéric Buclin2011-12-051-2/+6
* Bug 591610: Custom field doc doesn't include 'Bug ID' typeFrédéric Buclin2011-12-021-0/+5
* Bug 591636: "is mandatory" is not documented in the Custom Fields sectionFrédéric Buclin2011-12-021-0/+10
* Bug 706118: Session token not deleted during a bug mass-changeFrédéric Buclin2011-11-291-0/+3
* Bug 277073: Make whining trap errors thrown by Search.pmFrédéric Buclin2011-11-282-2/+12
* Fix missing-space bugs in error messages. a=LpSolit.Gervase Markham2011-11-013-6/+6
* Bug 685552 - Email auto-completion causes server to thrashDavid Lawrence2011-10-244-3/+17
* Bug 686860: Correctly calculate Hours Worked in buglistsAlexei Volkov2011-10-181-1/+1
* Bug 691243: Fix typoMatt Selsky2011-10-151-1/+1
* Bug 620694: MySQL is not 'required' RDBMS for BugzillaMatt Selsky2011-10-151-1/+1
* Bug 445804: Suggested crontab configuration opens security holeMatt Selsky2011-10-151-3/+3
* Bug 691845: importxml.pl complains if an open bug has the resolution field se...Frédéric Buclin2011-10-081-9/+6
* $user->is_mover no longer exists, see bug 556422Frédéric Buclin2011-10-041-6/+0
* Bug 682203 - migrate.pl fails at requirements check.Marc Schumann2011-08-311-0/+1
* Bug 680780: Advanced Search: help for field Comment is missing a spaceFrédéric Buclin2011-08-301-1/+1
* Bug 682747: Wrong check in editusers.cgiFrédéric Buclin2011-08-301-1/+1