X-Git-Url: https://vcs.fsf.org/?p=squirrelmail.git;a=blobdiff_plain;f=ChangeLog;h=30557ce21f7eab88355c9948534fbc66f34f3942;hp=f10bd73909dc00f296d759c85c9e681b6b2205e3;hb=bb27e0c3c1046bc2e6f63aac5ed105d28dc17a36;hpb=13fb02bbf189cf664a8dd72c22e9f681e5683ada;ds=sidebyside diff --git a/ChangeLog b/ChangeLog index f10bd739..30557ce2 100644 --- a/ChangeLog +++ b/ChangeLog @@ -13,8 +13,37 @@ Version 1.5.2 - CVS pure TLS not to be used to assume STARTTLS. - Fixed quotes in configuration strings in administrator plugin. - Fixed View as HTML link so it doesn't forget it was part of a seach result. - - + - Don't use delimiter in IMAP subscription command, when noselect folder is + created. + - Security: Possible cookie theft in src/redirect.php if + register_globals is enabled, and malicous site is running + in same domain. + - Stop URL parsing, if 8bit symbols or HTML entities are detected (#1356798). + - Added new color themes by Jeremy Landes, Tammi Maggard and Lucas Austin-Howe + (#1378332), (#1377567), (#1377529), (#1377528), (#1377527), (#1377526), + (#1377525), (#1393188). + - Issue loading options page always loaded the prefs + initial_value on display, instead of the users' value. + - Adding the message_body hook to src/view_html.php and src/view_text.php, + allowing display of unsafe images when viewing HTML attachments and when + HTML is in an