X-Git-Url: https://vcs.fsf.org/?a=blobdiff_plain;f=ChangeLog;h=ab855463bc9ceb94da5211b3203a636c5f498d10;hb=26aefb60aa6b0741bc16ab1ac7892a16efb53a25;hp=3b18f2336c0c4e9d78add4b71892a210a606a7b7;hpb=f5a2d7b40d304b6d68f7cf33b3a525b59c7d2869;p=squirrelmail.git diff --git a/ChangeLog b/ChangeLog index 3b18f233..ab855463 100644 --- a/ChangeLog +++ b/ChangeLog @@ -18,8 +18,121 @@ Version 1.5.2 - CVS - Security: Possible cookie theft in src/redirect.php if register_globals is enabled, and malicous site is running in same domain. - - + - Stop URL parsing, if 8bit symbols or HTML entities are detected (#1356798). + - Added new color themes by Jeremy Landes, Tammi Maggard and Lucas Austin-Howe + (#1378332), (#1377567), (#1377529), (#1377528), (#1377527), (#1377526), + (#1377525), (#1393188). + - Issue loading options page always loaded the prefs + initial_value on display, instead of the users' value. + - Adding the message_body hook to src/view_html.php and src/view_text.php, + allowing display of unsafe images when viewing HTML attachments and when + HTML is in an