Commit Graph

9 Commits

Author SHA1 Message Date
jasper
17019fba7a security update to 2.10.19, fixes CVE-2012-3952
phplist "unconfirmed" Cross-Site Scripting Vulnerability
2012-08-17 08:58:46 +00:00
sthen
4d751be561 SECURITY update to phplist 2.10.18
"Desc: Input passed via the parameter 'sortby' is not properly
sanitised before being returned to the user or used in SQL queries.
This can be exploited to manipulate SQL queries by injecting
arbitrary SQL code. The param 'num' is vulnerable to a XSS issue
where the attacker can execute arbitrary HTML and script code in
a user's browser session in context of an affected site."

Security issues require admin login.
2012-06-16 11:37:20 +00:00
jasper
1c6e5647b6 - update to phplist-2.10.17
fixes SA45495 phpList Multiple Vulnerabilities
2011-11-06 20:10:45 +00:00
sthen
26b7f15949 security update to phplist 2.10.14.
(though no ports@ readers appear to use it..)
2011-06-24 09:04:30 +00:00
jasper
a1a337b880 - Security update of phplist to 2.10.13 which among other regular bugs fixed
CVE-2011-0748, phplist Cross-Site Request Forgery Vulnerability
2011-04-14 07:10:44 +00:00
mbalmer
5d65d31c19 Maintenance update to PHPList 2.10.5 2008-01-09 11:30:23 +00:00
espie
d4ebcd974d more base64 checksums 2007-04-05 17:26:05 +00:00
mbalmer
c36e4a167e Update to PHPList 2.10.3, which contains some of my additions and patches.
The full release information can be found on www.phplist.com.
2006-10-07 10:36:37 +00:00
mbalmer
4d6fc486f2 phplist is a dual opt-in mailing list manager that is web based (uses PHP5
and MySQL).
2006-10-03 13:42:10 +00:00