[Savannah-help-public] [sr #107269] gplv3-or-later not offered to new projects

2010-02-13 Thread Karl Berry
URL: Summary: gplv3-or-later not offered to new projects Project: Savannah Administration Submitted by: karl Submitted on: Sat 13 Feb 2010 03:50:07 PM PST Category: Savannah websi

[Savannah-help-public] [sr #106475] Cross-site scripting using feedback variable

2010-02-13 Thread Matt McCutchen
Follow-up Comment #3, sr #106475 (project administration): The XSS does not seem to work any more. Still, it's not comforting that an attacker can place arbitrary text in an apparently trusted part of the Savannah UI. Example.

[Savannah-help-public] [sr #107055] XSRF

2010-02-13 Thread Matt McCutchen
Follow-up Comment #1, sr #107055 (project administration): Confirmed. ___ Reply to this item at: ___ Message sent via/by Savannah http://savannah

[Savannah-help-public] [sr #107268] Verification of account email changes is ineffective

2010-02-13 Thread Matt McCutchen
URL: Summary: Verification of account email changes is ineffective Project: Savannah Administration Submitted by: hashproduct Submitted on: Sat 13 Feb 2010 05:44:37 PM EST Categor