Commit Graph

1135 Commits

Author SHA1 Message Date
uwe.tews@googlemail.com
b67c7082a7 - escape Smarty error messages to avoid possible script execution 2012-09-24 20:05:15 +00:00
Uwe.Tews
abf692eaf7 - fixed security hole in {math} plugin 2010-04-17 10:19:47 +00:00
Uwe.Tews
7d42f5efb9 - bugfix cycle plugin 2009-11-17 20:20:17 +00:00
monte.ohrt
5d2ed61c31 Revert delimiter code change 2009-11-17 01:29:01 +00:00
monte.ohrt
243531e4a3 change split() to preg_split(), deprecated in php 5.3 2009-07-05 04:58:48 +00:00
monte.ohrt
443e36f1a8 revert super global access changes, and instead use ALLOW_SUPER_GLOBALS for security measures 2009-06-17 14:39:24 +00:00
monte.ohrt
4014a41c02 update super global access to gracefully handle unset super global vars 2009-06-15 14:04:53 +00:00
monte.ohrt
2172df777a fix E_NOTICE Errors 2009-05-23 20:59:25 +00:00
monte.ohrt
25be1792e6 fix E_NOTICE with sessions disabled 2009-05-17 14:48:19 +00:00
monte.ohrt
e11b8c6d7a rename supers to _supers 2009-05-16 23:27:22 +00:00
monte.ohrt
2919f9a608 fix problem with super globals and isset() 2009-05-16 23:23:49 +00:00
monte.ohrt
5220455ae5 update NEWS file and dev version numbers 2009-05-14 13:18:50 +00:00
monte.ohrt
c82db76539 strip backticks from math equations 2009-05-13 15:37:29 +00:00
monte.ohrt
34cadb491c disallow writing to super globals from within the template. also add ability to disable super global access with security enabled 2009-04-30 21:51:19 +00:00
monte.ohrt
7ba848416c let smarty throw error when template source is not readable 2009-04-27 15:46:54 +00:00
monte.ohrt
0bde5c5477 revert method chaining code in compiler 2009-03-28 20:28:17 +00:00
monte.ohrt
a2db07cb46 update version numbers in svn 2008-12-17 20:08:17 +00:00
monte.ohrt
835fd9e69d back out method chaining, some verions of PCRE throw errors 2008-12-08 15:10:03 +00:00
monte.ohrt
1fe6ad061c patch for security, php executed in templates 2008-09-22 19:26:32 +00:00
monte.ohrt
2e61902cdf revert patch for secuity hole, update site url 2008-09-22 15:29:16 +00:00
Uwe.Tews
7665ecf8cc 2008-09-18 21:04:38 +00:00
Uwe.Tews
4ed34dc334 2008-09-18 21:04:12 +00:00
Uwe.Tews
d195b96411 - fix function injection security hole closed (U.Tews) 2008-09-18 21:03:32 +00:00
Uwe.Tews
0e627cb83e - fix pass expiration time in cache_handler_func call. (U.Tews) 2008-09-10 15:57:27 +00:00
Uwe.Tews
ece447453f 2008-09-09 15:37:20 +00:00
Uwe.Tews
a21446a764 Updated to allow method chaining for PHP4 and PHP5 (U.Tews) 2008-09-08 22:31:19 +00:00
monte.ohrt
e4a5b1f8fc update version numbers (again) 2008-08-15 21:14:45 +00:00
monte.ohrt
54a6a542dd update version numbers 2008-08-15 21:12:56 +00:00
Uwe.Tews
1dd680df13 fix that function results can be used together with conditions like "is even" at the {if} tag (U.Tews) 2008-08-12 18:17:51 +00:00
monte.ohrt
380e0d0d6b fix problem with /e security check on arrays using regex_replace 2008-08-06 17:07:15 +00:00
monte.ohrt
f9891ce80c fix bug with replacing cache tags (thanks mankyd) 2008-08-06 16:46:30 +00:00
messju
2e90a041fb fix handling of non-empty <pre>-tags and empty <textarea>- and <script>-tags 2008-07-31 13:52:48 +00:00
monte.ohrt
7aa88fbace revert to last versio 2008-03-05 13:47:28 +00:00
monte.ohrt
6be653b234 remove irrelevant ? in preg pattern 2008-03-05 03:08:50 +00:00
monte.ohrt
cc040d7350 fix bug in regex_replace where a \0 character ingores the rest of the line 2008-02-11 15:55:31 +00:00
mohrt
06acedfc20 fix typo 2007-09-16 14:47:53 +00:00
mohrt
3cb64d6a44 add append feature to capture 2007-08-01 13:34:39 +00:00
danilo
c6a760fa7e Added the ability to (un)register multiple filters of the same type with the same method name but different class name. Before it was not possible due to the fact that only the method name was used to distinguish between different filters of the same type. This does however not allow (same as before) to register multiple filters of the same type with the same method and class name (i.e. different instances of the same class). 2007-06-18 14:29:00 +00:00
messju
f0c0589b08 fixed typo 2007-05-29 10:20:26 +00:00
messju
2aae91c920 fixed calling registered objects' methods with an empty argument list.
thanks marcello
2007-05-11 13:45:36 +00:00
mohrt
87dec363dc update version numbers 2007-03-08 19:11:22 +00:00
mohrt
e4ed759394 fix html_select_date separator when parts are missing (thanks to kayk for the patch) 2007-03-06 20:13:55 +00:00
messju
1f2852d1da bumped version number 2007-03-06 10:40:06 +00:00
messju
190c012758 fixed detection of non-cached block when writing compiled includes 2007-03-06 10:36:01 +00:00
danilo
edf49d5570 Applied boots clean up patch and removed commented out code.
Updated NEWS file
2007-03-01 18:18:56 +00:00
danilo
a03bcd353f Updated smarty_core_write_file() and smarty_modifier_date_format() to speed up Windows detection.
Emulated more parameters for Windows in smarty_modifier_date_format() and fixed some old ones.
Updated the docs to tell what parameters are emulated on Windows.
Updated NEWS file.
2007-02-27 22:22:09 +00:00
danilo
a9c19850bb Modified _(push|pop)_cacheable_state() to embedd alternate syntax. See this bug report: http://www.phpinsider.com/smarty-forum/viewtopic.php?t=10502 2007-02-27 11:14:10 +00:00
mohrt
b90563045e escape creating of language=php from interleaving 2007-02-23 19:40:01 +00:00
mohrt
2c90488fd2 add removed line back in 2007-02-23 16:28:34 +00:00
mohrt
5a1db056c7 fix up last patch, remove unnecessary lines 2007-02-23 16:18:02 +00:00