summaryrefslogtreecommitdiff
path: root/t/t3040-subprojects-basic.sh
diff options
context:
space:
mode:
authorLibravatar Jeff King <peff@peff.net>2012-11-12 16:34:28 -0500
committerLibravatar Jeff King <peff@peff.net>2012-11-12 16:34:53 -0500
commit0f0ecf68b31303de7cb428554e27d433fe62180e (patch)
treed1f8f5902fb5ff6dd45ba21e6fce2a5d6e7f185d /t/t3040-subprojects-basic.sh
parentGit 1.7.12.4 (diff)
downloadtgif-0f0ecf68b31303de7cb428554e27d433fe62180e.tar.xz
gitweb: escape html in rss title
The title of an RSS feed is generated from many components, including the filename provided as a query parameter, but we failed to quote it. Besides showing the wrong output, this is a vector for XSS attacks. Signed-off-by: Jeff King <peff@peff.net>
Diffstat (limited to 't/t3040-subprojects-basic.sh')
0 files changed, 0 insertions, 0 deletions