Bug#582691: patch for sql injection

2010-06-10 Thread sean finney
just for the record, i haven't yet uploaded a new unstable version yet, mostly because i was waiting for upstream to roll out a fix for the 0.8.7f release, which apparently contained a number of regressions. If I don't see any movement on that by the end of the weekend i'll go ahead and look at ap

Bug#582691: patch for sql injection

2010-06-10 Thread Nico Golde
Hi, attached is a patch for CVE-2010-2092. Cheers Nico --- graph.php 2009-06-28 18:07:11.0 +0200 +++ graph.php.new 2010-06-10 17:41:07.0 +0200 @@ -33,7 +33,7 @@ include_once("./include/top_graph_header.php"); /* = input validation = */ -input_vali