[otrs-cvs] ITSMChangeManagement/Kernel/System/ITSMChange Template.pm, 1.60, 1.60.2.1 ITSMWorkOrder.pm, 1.132.2.1, 1.132.2.2
"CVS commits notifications of OTRS.org" <[email protected]> Fri, 28 Jun 2013 13:04:27 +0000
| Newsgroups | gmane.comp.otrs.cvs |
|---|---|
| Message-ID | <[email protected]> |
Comments:
Update of /home/cvs/ITSMChangeManagement/Kernel/System/ITSMChange
In directory lancelot:/tmp/cvs-serv17507/Kernel/System/ITSMChange
Modified Files:
Tag: rel-3_1
Template.pm ITSMWorkOrder.pm
Log Message:
Improved quoting for integer values to avoid possible security issues.
Author: ub
Index: Template.pm
===================================================================
RCS file: /home/cvs/ITSMChangeManagement/Kernel/System/ITSMChange/Template.pm,v
retrieving revision 1.60
retrieving revision 1.60.2.1
diff -2 -u -d -r1.60 -r1.60.2.1
--- Template.pm 2 Apr 2012 15:56:21 -0000 1.60
+++ Template.pm 28 Jun 2013 13:04:22 -0000 1.60.2.1
@@ -1,5 +1,5 @@
# --
# Kernel/System/ITSMChange/Template.pm - all template functions
-# Copyright (C) 2001-2012 OTRS AG, http://otrs.org/
+# Copyright (C) 2001-2013 OTRS AG, http://otrs.org/
# --
# $Id$
@@ -808,7 +808,7 @@
next ARRAYPARAM if !@{ $Param{$ArrayParam} };
- # quote
+ # quote as integer
for my $OneParam ( @{ $Param{$ArrayParam} } ) {
- $OneParam = $Self->{DBObject}->Quote($OneParam);
+ $OneParam = $Self->{DBObject}->Quote( $OneParam, 'Integer' );
}
Author: ub
Index: ITSMWorkOrder.pm
===================================================================
RCS file: /home/cvs/ITSMChangeManagement/Kernel/System/ITSMChange/ITSMWorkOrder.pm,v
retrieving revision 1.132.2.1
retrieving revision 1.132.2.2
diff -2 -u -d -r1.132.2.1 -r1.132.2.2
--- ITSMWorkOrder.pm 21 Nov 2012 17:58:05 -0000 1.132.2.1
+++ ITSMWorkOrder.pm 28 Jun 2013 13:04:22 -0000 1.132.2.2
@@ -1,5 +1,5 @@
# --
# Kernel/System/ITSMChange/ITSMWorkOrder.pm - all workorder functions
-# Copyright (C) 2001-2012 OTRS AG, http://otrs.org/
+# Copyright (C) 2001-2013 OTRS AG, http://otrs.org/
# --
# $Id$
@@ -1398,7 +1398,7 @@
next ARRAYPARAM if !@{ $Param{$ArrayParam} };
- # quote
+ # quote as integer
for my $OneParam ( @{ $Param{$ArrayParam} } ) {
- $OneParam = $DBObject->Quote($OneParam);
+ $OneParam = $DBObject->Quote( $OneParam, 'Integer' );
}
---------------------------------------------------------------------
OTRS mailing list: cvs-log - Webpage: http://otrs.org/
Archive: http://lists.otrs.org/pipermail/cvs-log
To unsubscribe: http://lists.otrs.org/cgi-bin/listinfo/cvs-log