ChangeLog update

This commit is contained in:
2007-06-17 01:31:17 +00:00
parent fde56bd858
commit bb433c26c1

View File

@ -1,3 +1,11 @@
2007-06-16 Stefan Esser <php@nopiracy.de>
* ext/session/session.c:
Fix attribute injection security bug correctly by URL encoding session
name and session value. (in future maybe encode path/domain, too)
Remove backward compatibility breaking blacklist of characters.
2007-06-15 Stanislav Malyshev <stas@zend.com>
* ext/session/session.c