|  | 84467fbb8d | Restrict opening of files outside the Mibew installation | 2013-09-13 14:34:59 +04:00 |  | 
			
				
					|  | afa06b21e2 | Bug fix Properly check file handler before making use of it in common.php | 2013-09-13 14:34:32 +04:00 |  | 
			
				
					|  | 6747e2f557 | Improve algorithm of setting and storing locale setting | 2013-09-13 13:36:04 +04:00 |  | 
			
				
					|  | 2559630e8f | Add verification of values of the default and home locales | 2013-09-11 20:18:26 +04:00 |  | 
			
				
					|  | 097ee2b0d9 | Fix files' permissions | 2013-09-11 19:35:17 +04:00 |  | 
			
				
					|  | 50c0b50abf | Sanitize database tables prefix | 2013-09-10 19:10:26 +04:00 |  | 
			
				
					|  | f26af7f05d | Make headers more safe | 2013-09-10 17:41:54 +04:00 |  | 
			
				
					|  | b42f5bdd0d | Sanitize path to application and remove extra slashes from it | 2013-09-10 17:28:22 +04:00 |  | 
			
				
					|  | 92847d1a52 | Fix multiple (potential) SQL Injections | 2013-09-10 16:21:34 +04:00 |  | 
			
				
					|  | 2532f3bc01 | Enable default conversion of single quotes during HTML entities conversion | 2013-09-06 17:08:27 +04:00 |  | 
			
				
					|  | 441e88dfa9 | Remove redundant whitespaces | 2013-09-06 15:35:11 +04:00 |  | 
			
				
					|  | 0f86f558ec | Fix HTML attributes markup | 2013-09-06 15:34:42 +04:00 |  | 
			
				
					|  | 621f5951c4 | Fix paths in login-related forms | 2013-09-06 14:34:44 +04:00 |  | 
			
				
					|  | 4e6eff55e5 | Mark necessary comment field in ban form | 2013-09-06 14:33:11 +04:00 |  | 
			
				
					|  | 03265a1fb0 | Fix multiple CSRF vulnerabilities | 2013-09-06 14:32:25 +04:00 |  | 
			
				
					|  | 9aef0fb2d4 | Fix multiple XSS vulnerabilities (including CVE-2012-0829) | 2013-09-06 14:31:07 +04:00 |  | 
			
				
					| 
							
							
								 Dmitriy Simushev | 3ee7fca025 | Add captcha to pre-chat survey | 2013-08-28 12:33:25 +04:00 |  | 
			
				
					|  | 845d250b88 | Fix steps enumeration in README file | 2013-08-04 13:38:17 +04:00 |  | 
			
				
					|  | efe6caee71 | Mibew Tray 1.1.1 release Update links to an actual mibew domain in Mibew Tray application (thanks to Nemesis0one) | 2013-07-31 16:38:10 +04:00 |  | 
			
				
					|  | dcd5ecebfa | 1.6.5 released | 2013-07-24 17:23:48 +04:00 |  | 
			
				
					|  | 32b9ba862b | Update db and features versions | 2013-07-24 15:50:00 +04:00 |  | 
			
				
					|  | eb65ec9329 | Update translations (da, de, fi, it, pt-br) | 2013-07-24 15:49:22 +04:00 |  | 
			
				
					|  | d6c18a5ef7 | Update javascripts: version changed to 1.6.5 | 2013-07-24 01:47:07 +04:00 |  | 
			
				
					|  | 3ea9c6c893 | Update copyright notice | 2013-07-24 01:20:36 +04:00 |  | 
			
				
					|  | 4cd7bab1be | Improve packaging script | 2013-07-24 00:42:43 +04:00 |  | 
			
				
					|  | 95d95daa34 | Update localization constants | 2013-07-24 00:42:23 +04:00 |  | 
			
				
					| 
							
							
								 Dmitriy Simushev | b5d05f5411 | Update license info in license.php | 2013-07-24 00:08:46 +04:00 |  | 
			
				
					| 
							
							
								 Evgeny Gryaznov | 13ca97f10d | update headers | 2013-03-06 22:56:55 +01:00 |  | 
			
				
					| 
							
							
								 Evgeny Gryaznov | 4f483abe26 | Merge branch 'v1.6.x' | 2013-03-06 22:52:38 +01:00 |  | 
			
				
					| 
							
							
								 Evgeny Gryaznov | 13622c46b3 | update README | 2013-03-06 22:42:25 +01:00 |  | 
			
				
					| 
							
							
								 Evgeny Gryaznov | 7bdd14c790 | remove eclipse files; update version to 1.6.5; fix headers | 2013-03-06 22:32:31 +01:00 |  | 
			
				
					| 
							
							
								 Evgeny Gryaznov | 98aad6e490 | apache 2 license in php headers | 2013-03-06 22:22:53 +01:00 |  | 
			
				
					| 
							
							
								 Evgeny Gryaznov | 3741e57eab | apache 2 license (started); upgrade version to 1.6.5 | 2013-03-05 00:24:26 +01:00 |  | 
			
				
					| 
							
							
								 Evgeny Gryaznov | c50d60730c | fix move_uploaded_file errors | 2013-03-05 00:03:39 +01:00 |  | 
			
				
					| 
							
							
								 Evgeny Gryaznov | dd6632ffdf | format the code; remove comments in the client code; move csrfchecktoken() right after check_login() | 2012-06-27 10:11:40 +02:00 |  | 
			
				
					| 
							
							
								 YuFei Zhu | 2d04bbe4ee | add csrf token to translate view | 2012-05-01 13:21:49 +01:00 |  | 
			
				
					| 
							
							
								 YuFei Zhu | 22916ce8a0 | add csrf token to performance and features views | 2012-05-01 13:20:03 +01:00 |  | 
			
				
					| 
							
							
								 YuFei Zhu | 7f8b2fca89 | update token methods to ensure csrf token is always get setted | 2012-05-01 13:18:42 +01:00 |  | 
			
				
					| 
							
							
								 YuFei Zhu | e3b8848f78 | update comment for avatar csrf, and add csrf token check to permission page | 2012-05-01 13:02:34 +01:00 |  | 
			
				
					| 
							
							
								 YuFei Zhu | e4be5385ca | add csrf token check to avatar upload | 2012-05-01 12:58:05 +01:00 |  | 
			
				
					| 
							
							
								 YuFei Zhu | 092ebd16ba | added auth token for delete offline messages check for csrf | 2012-04-30 17:14:44 +01:00 |  | 
			
				
					| 
							
							
								 YuFei Zhu | 8abf075e2f | enable act=del url check for auth tokens for csrf attacks | 2012-04-30 17:09:11 +01:00 |  | 
			
				
					| 
							
							
								 YuFei Zhu | b84b439358 | having token checks on POST forms | 2012-04-30 16:41:55 +01:00 |  | 
			
				
					| 
							
							
								 Evgeny Gryaznov | 1ab3efb86f | login & reset password pages: default value for login where possible; update ru | 2012-03-14 22:26:44 +01:00 |  | 
			
				
					| 
							
							
								 Dmitriy Simushev | 7b35045f06 | Fixed the bug related with the need to enter passwords when you change the profile of any operator. | 2012-03-14 22:26:44 +01:00 |  | 
			
				
					|  | 4bb79cb7cb | Fix bug in old threads cleansing | 2012-03-14 22:26:44 +01:00 |  | 
			
				
					| 
							
							
								 Dmitriy Simushev | 323a7f2fcd | Added closing threads by timeout | 2012-03-14 22:26:39 +01:00 |  | 
			
				
					| 
							
							
								 Dmitriy Simushev | 36a2d977a0 | Open mibew.org link in the bottom of operators pages in a new window | 2012-03-12 22:43:27 +01:00 |  | 
			
				
					| 
							
							
								 Dmitriy Simushev | d0bd084d1c | Fixed the Blue Screen in Google Chrome 17+ | 2012-03-12 22:30:11 +01:00 |  | 
			
				
					| 
							
							
								 Dmitriy Simushev | 8c69f5ad09 | Fixed js bug with submit buttons in restore and reset password forms | 2012-03-12 22:24:01 +01:00 |  |