Services
24×7×365 Technical Support
Migration to PostgreSQL
High Availability Deployment
Database Audit
Remote DBA for PostgreSQL
Products
Postgres Pro Enterprise
Postgres Pro Standard
Cloud Solutions
Postgres Extensions
Resources
Blog
Documentation
Webinars
Videos
Presentations
Community
Events
Training Courses
Books
Demo Database
Mailing List Archives
About
Leadership team
Partners
Customers
In the News
Press Releases
Press Info
Services
24×7×365 Technical Support
Migration to PostgreSQL
High Availability Deployment
Database Audit
Remote DBA for PostgreSQL
Products
Postgres Pro Enterprise
Postgres Pro Standard
Cloud Solutions
Postgres Extensions
Resources
Blog
Documentation
Webinars
Videos
Presentations
Community
Events
Training Courses
Books
Demo Database
Mailing List Archives
About
Leadership team
Partners
Customers
In the News
Press Releases
Press Info
Facebook
Downloads
Home
>
mailing lists
Re: [pgadmin-hackers] security bug (with patch-fix) -- need moreHTML-escaping for working with tree-nodes - Mailing list pgadmin-hackers
From
Dave Page
Subject
Re: [pgadmin-hackers] security bug (with patch-fix) -- need moreHTML-escaping for working with tree-nodes
Date
May 10, 2017
10:59:05
Msg-id
CA+OCxoxHMMzgFCQ8hmMx9AtoYcRpVO2KJqLKJNWMf9=KYEJ7qw@mail.gmail.com
Whole thread
Raw
In response to
Re: [pgadmin-hackers] security bug (with patch-fix) -- need moreHTML-escaping for working with tree-nodes
(Ashesh Vashi <ashesh.vashi@enterprisedb.com>)
Responses
Re: [pgadmin-hackers] security bug (with patch-fix) -- need moreHTML-escaping for working with tree-nodes
List
pgadmin-hackers
Tree view
On Wed, May 10, 2017 at 8:56 AM, Ashesh Vashi
<
ashesh.vashi@enterprisedb.com
>
wrote:
Thanks.
Committed!
I agree with the change from a preventative/safety perspective, though I'm struggling to classify it as a security issue, given that collections are always named by the code and not from user input.
Am I missing something?
--
Dave Page
Blog:
http://pgsnake.blogspot.com
Twitter: @pgsnake
EnterpriseDB UK:
http://www.enterprisedb.com
The Enterprise PostgreSQL Company
pgadmin-hackers
by date:
Previous
From:
Ashesh Vashi
Date:
10 May 2017, 10:56:51
Subject:
Re: [pgadmin-hackers] security bug (with patch-fix) -- need moreHTML-escaping for working with tree-nodes
Next
From:
Ashesh Vashi
Date:
10 May 2017, 11:00:57
Subject:
Re: [pgadmin-hackers] security bug (with patch-fix) -- need moreHTML-escaping for working with tree-nodes
Есть вопросы? Напишите нам!
Соглашаюсь с условиями обработки персональных данных
I confirm that I have read and accepted PostgresPro’s
Privacy Policy
.
I agree to get Postgres Pro discount offers and other marketing communications.
✖
×
×
Everywhere
Documentation
Mailing list
List:
all lists
pgsql-general
pgsql-hackers
buildfarm-members
pgadmin-hackers
pgadmin-support
pgsql-admin
pgsql-advocacy
pgsql-announce
pgsql-benchmarks
pgsql-bugs
pgsql-chat
pgsql-cluster-hackers
pgsql-committers
pgsql-cygwin
pgsql-docs
pgsql-hackers-pitr
pgsql-hackers-win32
pgsql-interfaces
pgsql-jdbc
pgsql-jobs
pgsql-novice
pgsql-odbc
pgsql-patches
pgsql-performance
pgsql-php
pgsql-pkg-debian
pgsql-pkg-yum
pgsql-ports
pgsql-rrreviewers
pgsql-ru-general
pgsql-sql
pgsql-students
pgsql-testers
pgsql-translators
pgsql-www
psycopg
Period
anytime
within last day
within last week
within last month
within last 6 months
within last year
Sort by
date
reverse date
rank
Services
24×7×365 Technical Support
Migration to PostgreSQL
High Availability Deployment
Database Audit
Remote DBA for PostgreSQL
Products
Postgres Pro Enterprise
Postgres Pro Standard
Cloud Solutions
Postgres Extensions
Resources
Blog
Documentation
Webinars
Videos
Presentations
Community
Events
Training Courses
Books
Demo Database
Mailing List Archives
About
Leadership team
Partners
Customers
In the News
Press Releases
Press Info
By continuing to browse this website, you agree to the use of cookies. Go to
Privacy Policy
.
I accept cookies