Date: Mon, 05 Feb 2007 19:53:43 -0800
From: Chris Travers <chris@metatrontech.com.>
To: [email protected]Subject: Unofficial SQL-Ledger patch for CVE-2007-0667
Content-Type: multipart/mixed;
boundary="------------000200030108070604010201"
X-Virus-Scanned: antivirus-gw at tyumen.ru
This is a multi-part message in MIME format.
--------------000200030108070604010201
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
This patch was made against SQL-Ledger 2.6.18 but just modifies a few
lines in the redirect() function in the Form.pm. I have decided that it
is probably best to release the patch and then wait a while before
releasing full disclosure. The author of SQL-Ledger has declined to use
this patch.
Best Wishes,
Chris Travers
--------------000200030108070604010201
Content-Type: text/x-patch;
name="sl-whitelist.patch"
Content-Transfer-Encoding: 7bit
Content-Disposition: inline;
filename="sl-whitelist.patch"
diff -C3 -r sql-ledger-orig/SL/Form.pm sql-ledger/SL/Form.pm