X-Git-Url: http://git.vanrenterghem.biz/git.ikiwiki.info.git/blobdiff_plain/1c65ca492295e754dfd9986f91b08eb0876d09b9..af63a2ebff201be7173a296aeabfc2713461c543:/debian/changelog diff --git a/debian/changelog b/debian/changelog index 5934958ce..86815828a 100644 --- a/debian/changelog +++ b/debian/changelog @@ -12,9 +12,8 @@ ikiwiki (1.46) unstable; urgency=low same time, and let the second person resolve the conflict. * Applied a patch from Michał to make the mercurial backend pass --quiet to hg. - * Fix a few bugs around page titles containing html. The worst of these - is an actual security hole as it allows insertion of html into the title - element of a page, which is not processed by the htmlscrubber. + * Fix a security hole that allowed a web user to insert + arbitrary html in the title of a page due to missing escaping. -- Joey Hess Wed, 21 Mar 2007 01:51:30 -0400