1
0
mirror of https://github.com/vichan-devel/vichan.git synced 2024-11-30 02:04:35 +01:00
vichan/inc/lib
8chan 3da946268a SECURITY: Poster IDs could reveal IPs across boards
Imagine the following scenario:

Alice has permission to view IPs on board A, and Bob has permissions to view IPs on board B.

If the post number was to match, and the same IP made both posts, A and B could trade user IPs which they wouldn't normally have permission to do so. This weird bug has already creeped up on 8chan.co and is now patched.
2014-10-07 08:16:21 -07:00
..
ayah Fix #13 2014-09-23 23:22:41 +00:00
geoip Revert "Update jQuery UI to 1.11.0, GeoIPv6 and IP library" 2014-07-06 03:50:16 +02:00
gettext SECURITY: remove XSS vulnerability 2014-03-30 16:40:14 +02:00
htmlpurifier-4.5.0 add htmlpurifier library 2014-09-23 23:25:04 +00:00
IP Revert "Update jQuery UI to 1.11.0, GeoIPv6 and IP library" 2014-07-06 03:50:16 +02:00
minify Updated minify, jQuery, MixItUp and Tooltipster 2014-05-07 11:17:32 +02:00
recaptcha inc/contrib -> inc/lib 2012-04-09 20:52:26 +10:00
Twig SECURITY: Poster IDs could reveal IPs across boards 2014-10-07 08:16:21 -07:00
webm restore compatibility with php < 5.5; fixes vichan-devel#86 2014-09-24 12:26:15 +02:00