pkgsrc/devel/mantis/PLIST

1149 lines
54 KiB
Text
Raw Normal View History

Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
@comment $NetBSD: PLIST,v 1.16 2012/12/25 21:49:05 ryoon Exp $
share/doc/mantis/CUSTOMIZATION
share/doc/mantis/INSTALL
share/examples/mantis/config_inc.php
share/examples/mantis/mantis.conf
share/examples/mantis/mantis_offline.php.sample
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/.mailmap
share/mantis/account_delete.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/account_manage_columns_page.php
share/mantis/account_page.php
2005-10-23 17:37:24 +02:00
share/mantis/account_prefs_inc.php
share/mantis/account_prefs_page.php
share/mantis/account_prefs_reset.php
share/mantis/account_prefs_update.php
share/mantis/account_prof_edit_page.php
share/mantis/account_prof_menu_page.php
share/mantis/account_prof_update.php
share/mantis/account_sponsor_page.php
share/mantis/account_sponsor_update.php
share/mantis/account_update.php
share/mantis/adm_config_delete.php
share/mantis/adm_config_report.php
share/mantis/adm_config_set.php
2005-10-23 17:37:24 +02:00
share/mantis/adm_permissions_report.php
share/mantis/admin/admin.css
share/mantis/admin/check.php
share/mantis/admin/copy_field.php
share/mantis/admin/db_stats.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/admin/email_queue.php
2005-10-23 17:37:24 +02:00
share/mantis/admin/index.php
share/mantis/admin/install.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/admin/install_functions.php
share/mantis/admin/install_helper_functions.php
2005-10-23 17:37:24 +02:00
share/mantis/admin/move_db2disk.php
share/mantis/admin/schema.php
share/mantis/admin/system_utils.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/admin/test_email.php
share/mantis/admin/test_icons.php
2005-10-23 17:37:24 +02:00
share/mantis/admin/test_langs.php
share/mantis/admin/upgrade_unattended.php
2005-10-23 17:37:24 +02:00
share/mantis/admin/upgrade_warning.php
share/mantis/api/soap/mantisconnect.php
share/mantis/api/soap/mc_account_api.php
share/mantis/api/soap/mc_api.php
share/mantis/api/soap/mc_config_api.php
share/mantis/api/soap/mc_config_defaults_inc.php
share/mantis/api/soap/mc_core.php
share/mantis/api/soap/mc_custom_field_api.php
share/mantis/api/soap/mc_enum_api.php
share/mantis/api/soap/mc_file_api.php
share/mantis/api/soap/mc_filter_api.php
share/mantis/api/soap/mc_issue_api.php
share/mantis/api/soap/mc_issue_attachment_api.php
share/mantis/api/soap/mc_project_api.php
share/mantis/api/soap/mc_project_attachment_api.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/api/soap/mc_tag_api.php
share/mantis/api/soap/mc_user_pref_api.php
share/mantis/api/soap/mc_user_profile_api.php
share/mantis/billing_inc.php
share/mantis/billing_page.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/browser_search_plugin.php
2005-10-23 17:37:24 +02:00
share/mantis/bug_actiongroup.php
share/mantis/bug_actiongroup_add_note_inc.php
share/mantis/bug_actiongroup_attach_tags_inc.php
share/mantis/bug_actiongroup_ext.php
share/mantis/bug_actiongroup_ext_page.php
2005-10-23 17:37:24 +02:00
share/mantis/bug_actiongroup_page.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/bug_actiongroup_update_product_build_inc.php
share/mantis/bug_actiongroup_update_severity_inc.php
2005-10-23 17:37:24 +02:00
share/mantis/bug_assign.php
share/mantis/bug_change_status_page.php
share/mantis/bug_file_add.php
share/mantis/bug_file_delete.php
share/mantis/bug_file_upload_inc.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/bug_monitor_add.php
share/mantis/bug_monitor_delete.php
2005-10-23 17:37:24 +02:00
share/mantis/bug_monitor_list_view_inc.php
share/mantis/bug_relationship_add.php
share/mantis/bug_relationship_delete.php
share/mantis/bug_relationship_graph.php
share/mantis/bug_relationship_graph_img.php
share/mantis/bug_reminder.php
share/mantis/bug_reminder_page.php
share/mantis/bug_report.php
share/mantis/bug_report_advanced_page.php
share/mantis/bug_report_page.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/bug_revision_drop.php
share/mantis/bug_revision_view_page.php
2005-10-23 17:37:24 +02:00
share/mantis/bug_set_sponsorship.php
share/mantis/bug_sponsorship_list_view_inc.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/bug_stick.php
2005-10-23 17:37:24 +02:00
share/mantis/bug_update.php
share/mantis/bug_update_advanced_page.php
share/mantis/bug_update_page.php
share/mantis/bug_view_advanced_page.php
share/mantis/bug_view_inc.php
share/mantis/bug_view_page.php
share/mantis/bugnote_add.php
share/mantis/bugnote_add_inc.php
2005-10-23 17:37:24 +02:00
share/mantis/bugnote_delete.php
share/mantis/bugnote_edit_page.php
share/mantis/bugnote_set_view_state.php
share/mantis/bugnote_stats_inc.php
2005-10-23 17:37:24 +02:00
share/mantis/bugnote_update.php
share/mantis/bugnote_view_inc.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/build.xml
2005-10-23 17:37:24 +02:00
share/mantis/changelog_page.php
share/mantis/config_defaults_inc.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/config_filter_defaults_inc.php
2005-10-23 17:37:24 +02:00
share/mantis/core.php
share/mantis/core/.htaccess
2005-10-23 17:37:24 +02:00
share/mantis/core/access_api.php
share/mantis/core/ajax_api.php
share/mantis/core/authentication_api.php
share/mantis/core/bug_api.php
share/mantis/core/bug_group_action_api.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/core/bug_revision_api.php
2005-10-23 17:37:24 +02:00
share/mantis/core/bugnote_api.php
share/mantis/core/category_api.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/core/cfdefs/cfdef_standard.php
share/mantis/core/classes/MantisColumn.class.php
share/mantis/core/classes/MantisCoreWikiPlugin.class.php
share/mantis/core/classes/MantisEnum.class.php
share/mantis/core/classes/MantisFilter.class.php
share/mantis/core/classes/MantisFormattingPlugin.class.php
share/mantis/core/classes/MantisPlugin.class.php
share/mantis/core/classes/MantisWikiPlugin.class.php
share/mantis/core/collapse_api.php
share/mantis/core/columns_api.php
share/mantis/core/compress_api.php
share/mantis/core/config_api.php
share/mantis/core/constant_inc.php
2005-10-23 17:37:24 +02:00
share/mantis/core/csv_api.php
share/mantis/core/current_user_api.php
share/mantis/core/custom_field_api.php
2005-10-23 17:37:24 +02:00
share/mantis/core/custom_function_api.php
share/mantis/core/database_api.php
share/mantis/core/date_api.php
2005-10-23 17:37:24 +02:00
share/mantis/core/email_api.php
share/mantis/core/email_queue_api.php
share/mantis/core/error_api.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/core/event_api.php
share/mantis/core/events_inc.php
share/mantis/core/excel_api.php
share/mantis/core/file_api.php
share/mantis/core/filter_api.php
Update to 1.1.2 - 0008974: [security] XSS Vulnerability in filters (thraxisp) - closed. - 0008975: [security] CSRF Vulnerabilities in user_create (jreese) - closed. - 0008976: [security] Remote Code Execution in adm_config (giallu) - closed. - 0009154: [security] arbitrary file inclusion through user preferences page (giallu) - closed. - 0008123: [administration] Adding a user requires "$g_lost_password_feature = ON" (giallu) - closed. - 0008924: [bugtracker] Port 8245: Target Version value lost in update issue page (giallu) - closed. - 0008886: [change log] Change Log shows duplicate entries (jreese) - closed. - 0008880: [db postgresql] Problem with date formatting in db_prepare_date function (giallu) - closed. - 0009176: [db postgresql] Port 0008699: Get Time Tracking Information return a SQL query error (vboctor) - closed. - 0009177: [filters] Port 0008916: Monitor by filter ignores show_monitor_list_threshold (vboctor) - closed. - 0008830: [installation] set_time_limit() doesn't work in PHP safe mode (daryn) - closed. - 0008858: [integration] DokuWiki integration: EMail notification on wiki page changes not working (vboctor) - closed. - 0008774: [localization] Complete Hungarian retranslation (vboctor) - closed. - 0009186: [localization] Port 0009046: French translation for $s_bug_assign_to_button (vboctor) - closed. - 0009178: [other] Fix memleak in string api (vboctor) - closed. - 0009208: [other] Several actions on bug update page lead into System Warning and App. Error (daryn) - closed. - 0008931: [relationships] Circle Relations cause roadmap to malfunction (jreese) - closed. - 0008853: [roadmap] Issue appears more than once in the Roadmap for a release. (jreese) - closed. - 0007764: [scripting] APPLICATION WARNING #100: Configuration option 'category_enum_string' not found (vboctor) - closed. - 0009183: [time tracking] Port 0008357: "Total time for issue" is shown even for users under threshold (vboctor) - closed. - 0009184: [time tracking] Port 0008849: Emails ignore time tracking view threshold (vboctor) - closed. - 0009185: [time tracking] Port 0008621: The expand icon is inverted for the Time tracking section (vboctor) - closed.
2008-06-21 17:17:00 +02:00
share/mantis/core/form_api.php
share/mantis/core/gpc_api.php
2005-10-23 17:37:24 +02:00
share/mantis/core/graphviz_api.php
share/mantis/core/helper_api.php
share/mantis/core/history_api.php
share/mantis/core/html_api.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/core/http_api.php
share/mantis/core/icon_api.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/core/json_api.php
share/mantis/core/lang_api.php
share/mantis/core/last_visited_api.php
share/mantis/core/ldap_api.php
share/mantis/core/logging_api.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/core/mobile_api.php
2005-10-23 17:37:24 +02:00
share/mantis/core/news_api.php
share/mantis/core/obsolete.php
share/mantis/core/php_api.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/core/plugin_api.php
2005-10-23 17:37:24 +02:00
share/mantis/core/prepare_api.php
share/mantis/core/print_api.php
share/mantis/core/profile_api.php
share/mantis/core/projax_api.php
share/mantis/core/project_api.php
share/mantis/core/project_hierarchy_api.php
2005-10-23 17:37:24 +02:00
share/mantis/core/relationship_api.php
share/mantis/core/relationship_graph_api.php
share/mantis/core/rss_api.php
Update to 1.1.2 - 0008974: [security] XSS Vulnerability in filters (thraxisp) - closed. - 0008975: [security] CSRF Vulnerabilities in user_create (jreese) - closed. - 0008976: [security] Remote Code Execution in adm_config (giallu) - closed. - 0009154: [security] arbitrary file inclusion through user preferences page (giallu) - closed. - 0008123: [administration] Adding a user requires "$g_lost_password_feature = ON" (giallu) - closed. - 0008924: [bugtracker] Port 8245: Target Version value lost in update issue page (giallu) - closed. - 0008886: [change log] Change Log shows duplicate entries (jreese) - closed. - 0008880: [db postgresql] Problem with date formatting in db_prepare_date function (giallu) - closed. - 0009176: [db postgresql] Port 0008699: Get Time Tracking Information return a SQL query error (vboctor) - closed. - 0009177: [filters] Port 0008916: Monitor by filter ignores show_monitor_list_threshold (vboctor) - closed. - 0008830: [installation] set_time_limit() doesn't work in PHP safe mode (daryn) - closed. - 0008858: [integration] DokuWiki integration: EMail notification on wiki page changes not working (vboctor) - closed. - 0008774: [localization] Complete Hungarian retranslation (vboctor) - closed. - 0009186: [localization] Port 0009046: French translation for $s_bug_assign_to_button (vboctor) - closed. - 0009178: [other] Fix memleak in string api (vboctor) - closed. - 0009208: [other] Several actions on bug update page lead into System Warning and App. Error (daryn) - closed. - 0008931: [relationships] Circle Relations cause roadmap to malfunction (jreese) - closed. - 0008853: [roadmap] Issue appears more than once in the Roadmap for a release. (jreese) - closed. - 0007764: [scripting] APPLICATION WARNING #100: Configuration option 'category_enum_string' not found (vboctor) - closed. - 0009183: [time tracking] Port 0008357: "Total time for issue" is shown even for users under threshold (vboctor) - closed. - 0009184: [time tracking] Port 0008849: Emails ignore time tracking view threshold (vboctor) - closed. - 0009185: [time tracking] Port 0008621: The expand icon is inverted for the Time tracking section (vboctor) - closed.
2008-06-21 17:17:00 +02:00
share/mantis/core/session_api.php
2005-10-23 17:37:24 +02:00
share/mantis/core/sponsorship_api.php
share/mantis/core/string_api.php
share/mantis/core/summary_api.php
share/mantis/core/tag_api.php
share/mantis/core/tokens_api.php
share/mantis/core/twitter_api.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/core/url_api.php
share/mantis/core/user_api.php
share/mantis/core/user_pref_api.php
share/mantis/core/utility_api.php
share/mantis/core/version_api.php
share/mantis/core/wiki_api.php
share/mantis/core/xmlhttprequest_api.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/css/calendar-blue.css
share/mantis/css/default.css
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/css/rtl.css
2005-10-23 17:37:24 +02:00
share/mantis/csv_export.php
share/mantis/doc/.htaccess
2005-10-23 17:37:24 +02:00
share/mantis/doc/CREDITS
share/mantis/doc/CUSTOMIZATION
share/mantis/doc/INSTALL
share/mantis/doc/LICENSE
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/doc/RELEASE
share/mantis/doc/en/administration_guide.html
share/mantis/doc/en/administration_guide.pdf
share/mantis/doc/en/administration_guide.txt
share/mantis/doc/en/developers.html
share/mantis/doc/en/developers.pdf
share/mantis/doc/en/developers.txt
share/mantis/docbook/README
share/mantis/docbook/administration_guide/en/Makefile
share/mantis/docbook/administration_guide/en/about.sgml
share/mantis/docbook/administration_guide/en/administration_guide.sgml
share/mantis/docbook/administration_guide/en/authentication.sgml
share/mantis/docbook/administration_guide/en/configuration.sgml
share/mantis/docbook/administration_guide/en/contributing.sgml
share/mantis/docbook/administration_guide/en/customizing_mantis.sgml
share/mantis/docbook/administration_guide/en/file-entities.ent
share/mantis/docbook/administration_guide/en/installation.sgml
share/mantis/docbook/administration_guide/en/page_descriptions.sgml
share/mantis/docbook/administration_guide/en/project_management.sgml
share/mantis/docbook/administration_guide/en/troubleshooting.sgml
share/mantis/docbook/administration_guide/en/user_management.sgml
share/mantis/docbook/administration_guide/en/workflow.sgml
share/mantis/docbook/developers/en/Makefile
share/mantis/docbook/developers/en/appendix.sgml
share/mantis/docbook/developers/en/contributers.sgml
share/mantis/docbook/developers/en/database.sgml
share/mantis/docbook/developers/en/developers.sgml
share/mantis/docbook/developers/en/event-reference-account.sgml
share/mantis/docbook/developers/en/event-reference-bug.sgml
share/mantis/docbook/developers/en/event-reference-filter.sgml
share/mantis/docbook/developers/en/event-reference-manage.sgml
share/mantis/docbook/developers/en/event-reference-notify.sgml
share/mantis/docbook/developers/en/event-reference-output.sgml
share/mantis/docbook/developers/en/event-reference.sgml
share/mantis/docbook/developers/en/events.sgml
share/mantis/docbook/developers/en/file-entities.ent
share/mantis/docbook/developers/en/integrators.sgml
share/mantis/docbook/developers/en/plugins-building-source.sgml
share/mantis/docbook/developers/en/plugins-building.sgml
share/mantis/docbook/developers/en/plugins.sgml
share/mantis/docbook/template/Makefile
share/mantis/docbook/template/chapter.sgml
share/mantis/docbook/template/file-entities.ent
share/mantis/docbook/template/stylesheet.css
share/mantis/docbook/template/stylesheet.dsl
share/mantis/docbook/template/template.sgml
share/mantis/excel_xml_export.php
2005-10-23 17:37:24 +02:00
share/mantis/file_download.php
share/mantis/history_inc.php
share/mantis/images/attachment.png
share/mantis/images/blank.gif
share/mantis/images/calendar-img.gif
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/images/clock.png
share/mantis/images/delete.png
share/mantis/images/dollars.gif
share/mantis/images/down.gif
share/mantis/images/favicon.ico
share/mantis/images/fileicons/chm.gif
share/mantis/images/fileicons/cpp.gif
share/mantis/images/fileicons/css.gif
share/mantis/images/fileicons/csv.gif
share/mantis/images/fileicons/doc.gif
share/mantis/images/fileicons/eml.gif
share/mantis/images/fileicons/generic.gif
share/mantis/images/fileicons/gif.gif
share/mantis/images/fileicons/html.gif
share/mantis/images/fileicons/jpg.gif
share/mantis/images/fileicons/mhtml.gif
share/mantis/images/fileicons/mid.gif
share/mantis/images/fileicons/mov.gif
share/mantis/images/fileicons/one.gif
share/mantis/images/fileicons/pcx.gif
share/mantis/images/fileicons/pdf.gif
share/mantis/images/fileicons/png.gif
share/mantis/images/fileicons/pot.gif
share/mantis/images/fileicons/pps.gif
share/mantis/images/fileicons/ppt.gif
share/mantis/images/fileicons/pub.gif
share/mantis/images/fileicons/reg.gif
share/mantis/images/fileicons/text.gif
share/mantis/images/fileicons/unknown.gif
share/mantis/images/fileicons/vsd.gif
share/mantis/images/fileicons/vsl.gif
share/mantis/images/fileicons/vst.gif
share/mantis/images/fileicons/wav.gif
share/mantis/images/fileicons/wbk.gif
share/mantis/images/fileicons/wri.gif
share/mantis/images/fileicons/xls.gif
share/mantis/images/fileicons/xlt.gif
share/mantis/images/fileicons/xml.gif
share/mantis/images/fileicons/zip.gif
share/mantis/images/ie.gif
share/mantis/images/mantis_logo.gif
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/images/mantis_logo.png
share/mantis/images/mantis_space.gif
share/mantis/images/minus.png
share/mantis/images/notice.gif
2005-10-23 17:37:24 +02:00
share/mantis/images/ok.gif
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/images/overdue.png
share/mantis/images/plus.png
share/mantis/images/priority_1.gif
share/mantis/images/priority_2.gif
share/mantis/images/priority_3.gif
2005-10-23 17:37:24 +02:00
share/mantis/images/priority_low_1.gif
share/mantis/images/priority_low_2.gif
share/mantis/images/priority_low_3.gif
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/images/priority_normal.gif
share/mantis/images/protected.gif
share/mantis/images/rel_dependant.png
share/mantis/images/rel_duplicate.png
share/mantis/images/rel_related.png
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/images/rss.png
share/mantis/images/synthese.gif
share/mantis/images/synthgraph.gif
share/mantis/images/unread.gif
share/mantis/images/up.gif
share/mantis/images/update.png
2005-10-23 17:37:24 +02:00
share/mantis/index.php
share/mantis/issues_rss.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/javascript/dev/addLoadEvent.js
share/mantis/javascript/dev/ajax.js
share/mantis/javascript/dev/common.js
share/mantis/javascript/dev/dynamic_filters.js
share/mantis/javascript/dev/jscalendar/calendar-blue.css
share/mantis/javascript/dev/jscalendar/calendar-setup.js
share/mantis/javascript/dev/jscalendar/calendar.js
share/mantis/javascript/dev/jscalendar/lang/calendar-en.js
share/mantis/javascript/dev/projax/MIT-LICENSE
share/mantis/javascript/dev/projax/builder.js
share/mantis/javascript/dev/projax/controls.js
share/mantis/javascript/dev/projax/dragdrop.js
share/mantis/javascript/dev/projax/effects.js
share/mantis/javascript/dev/projax/license.html
share/mantis/javascript/dev/projax/prototype.js
share/mantis/javascript/dev/projax/prototype_b.js
share/mantis/javascript/dev/projax/scriptaculous.js
share/mantis/javascript/dev/projax/slider.js
share/mantis/javascript/dev/time_tracking_stopwatch.js
share/mantis/javascript/dev/xmlhttprequest.js
share/mantis/javascript/min/addLoadEvent.js
share/mantis/javascript/min/ajax.js
share/mantis/javascript/min/common.js
share/mantis/javascript/min/dynamic_filters.js
share/mantis/javascript/min/jscalendar/calendar-blue.css
share/mantis/javascript/min/jscalendar/calendar-setup.js
share/mantis/javascript/min/jscalendar/calendar.js
share/mantis/javascript/min/jscalendar/lang/calendar-en.js
share/mantis/javascript/min/projax/MIT-LICENSE
share/mantis/javascript/min/projax/builder.js
share/mantis/javascript/min/projax/controls.js
share/mantis/javascript/min/projax/dragdrop.js
share/mantis/javascript/min/projax/effects.js
share/mantis/javascript/min/projax/license.html
share/mantis/javascript/min/projax/prototype.js
share/mantis/javascript/min/projax/prototype_b.js
share/mantis/javascript/min/projax/scriptaculous.js
share/mantis/javascript/min/projax/slider.js
share/mantis/javascript/min/time_tracking_stopwatch.js
share/mantis/javascript/min/xmlhttprequest.js
2005-10-23 17:37:24 +02:00
share/mantis/jump_to_bug.php
share/mantis/lang/.htaccess
share/mantis/lang/langreadme.txt
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/lang/strings_afrikaans.txt
share/mantis/lang/strings_amharic.txt
share/mantis/lang/strings_arabic.txt
share/mantis/lang/strings_arabicegyptianspoken.txt
share/mantis/lang/strings_belarusian_tarask.txt
share/mantis/lang/strings_breton.txt
share/mantis/lang/strings_bulgarian.txt
share/mantis/lang/strings_catalan.txt
share/mantis/lang/strings_chinese_simplified.txt
share/mantis/lang/strings_chinese_traditional.txt
share/mantis/lang/strings_croatian.txt
share/mantis/lang/strings_czech.txt
share/mantis/lang/strings_danish.txt
share/mantis/lang/strings_dutch.txt
share/mantis/lang/strings_english.txt
share/mantis/lang/strings_estonian.txt
share/mantis/lang/strings_finnish.txt
share/mantis/lang/strings_french.txt
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/lang/strings_galician.txt
share/mantis/lang/strings_german.txt
share/mantis/lang/strings_greek.txt
share/mantis/lang/strings_hebrew.txt
share/mantis/lang/strings_hungarian.txt
share/mantis/lang/strings_icelandic.txt
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/lang/strings_interlingua.txt
share/mantis/lang/strings_italian.txt
share/mantis/lang/strings_japanese.txt
share/mantis/lang/strings_korean.txt
share/mantis/lang/strings_latvian.txt
share/mantis/lang/strings_lithuanian.txt
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/lang/strings_macedonian.txt
share/mantis/lang/strings_norwegian_bokmal.txt
share/mantis/lang/strings_norwegian_nynorsk.txt
share/mantis/lang/strings_occitan.txt
share/mantis/lang/strings_polish.txt
2005-10-23 17:37:24 +02:00
share/mantis/lang/strings_portuguese_brazil.txt
share/mantis/lang/strings_portuguese_standard.txt
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/lang/strings_qqq.txt
share/mantis/lang/strings_ripoarisch.txt
share/mantis/lang/strings_romanian.txt
share/mantis/lang/strings_russian.txt
share/mantis/lang/strings_serbian.txt
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/lang/strings_serbian_latin.txt
share/mantis/lang/strings_slovak.txt
share/mantis/lang/strings_slovene.txt
share/mantis/lang/strings_spanish.txt
share/mantis/lang/strings_swedish.txt
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/lang/strings_swissgerman.txt
share/mantis/lang/strings_tagalog.txt
share/mantis/lang/strings_turkish.txt
share/mantis/lang/strings_ukrainian.txt
share/mantis/lang/strings_urdu.txt
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/lang/strings_vietnamese.txt
share/mantis/lang/strings_volapuk.txt
share/mantis/library/README.libs
share/mantis/library/adodb/adodb-active-record.inc.php
share/mantis/library/adodb/adodb-active-recordx.inc.php
share/mantis/library/adodb/adodb-csvlib.inc.php
share/mantis/library/adodb/adodb-datadict.inc.php
share/mantis/library/adodb/adodb-error.inc.php
share/mantis/library/adodb/adodb-errorhandler.inc.php
share/mantis/library/adodb/adodb-errorpear.inc.php
share/mantis/library/adodb/adodb-exceptions.inc.php
share/mantis/library/adodb/adodb-iterator.inc.php
share/mantis/library/adodb/adodb-lib.inc.php
share/mantis/library/adodb/adodb-memcache.lib.inc.php
share/mantis/library/adodb/adodb-pager.inc.php
share/mantis/library/adodb/adodb-pear.inc.php
share/mantis/library/adodb/adodb-perf.inc.php
share/mantis/library/adodb/adodb-php4.inc.php
share/mantis/library/adodb/adodb-time.inc.php
share/mantis/library/adodb/adodb-xmlschema.inc.php
share/mantis/library/adodb/adodb-xmlschema03.inc.php
share/mantis/library/adodb/adodb.inc.php
share/mantis/library/adodb/datadict/datadict-access.inc.php
share/mantis/library/adodb/datadict/datadict-db2.inc.php
share/mantis/library/adodb/datadict/datadict-firebird.inc.php
share/mantis/library/adodb/datadict/datadict-generic.inc.php
share/mantis/library/adodb/datadict/datadict-ibase.inc.php
share/mantis/library/adodb/datadict/datadict-informix.inc.php
share/mantis/library/adodb/datadict/datadict-mssql.inc.php
share/mantis/library/adodb/datadict/datadict-mssqlnative.inc.php
share/mantis/library/adodb/datadict/datadict-mysql.inc.php
share/mantis/library/adodb/datadict/datadict-oci8.inc.php
share/mantis/library/adodb/datadict/datadict-postgres.inc.php
share/mantis/library/adodb/datadict/datadict-sapdb.inc.php
share/mantis/library/adodb/datadict/datadict-sybase.inc.php
share/mantis/library/adodb/drivers/adodb-access.inc.php
share/mantis/library/adodb/drivers/adodb-ado.inc.php
share/mantis/library/adodb/drivers/adodb-ado5.inc.php
share/mantis/library/adodb/drivers/adodb-ado_access.inc.php
share/mantis/library/adodb/drivers/adodb-ado_mssql.inc.php
share/mantis/library/adodb/drivers/adodb-ads.inc.php
share/mantis/library/adodb/drivers/adodb-borland_ibase.inc.php
share/mantis/library/adodb/drivers/adodb-csv.inc.php
share/mantis/library/adodb/drivers/adodb-db2.inc.php
share/mantis/library/adodb/drivers/adodb-db2oci.inc.php
share/mantis/library/adodb/drivers/adodb-fbsql.inc.php
share/mantis/library/adodb/drivers/adodb-firebird.inc.php
share/mantis/library/adodb/drivers/adodb-ibase.inc.php
share/mantis/library/adodb/drivers/adodb-informix.inc.php
share/mantis/library/adodb/drivers/adodb-informix72.inc.php
share/mantis/library/adodb/drivers/adodb-ldap.inc.php
share/mantis/library/adodb/drivers/adodb-mssql.inc.php
share/mantis/library/adodb/drivers/adodb-mssql_n.inc.php
share/mantis/library/adodb/drivers/adodb-mssqlnative.inc.php
share/mantis/library/adodb/drivers/adodb-mssqlpo.inc.php
share/mantis/library/adodb/drivers/adodb-mysql.inc.php
share/mantis/library/adodb/drivers/adodb-mysqli.inc.php
share/mantis/library/adodb/drivers/adodb-mysqlpo.inc.php
share/mantis/library/adodb/drivers/adodb-mysqlt.inc.php
share/mantis/library/adodb/drivers/adodb-netezza.inc.php
share/mantis/library/adodb/drivers/adodb-oci8.inc.php
share/mantis/library/adodb/drivers/adodb-oci805.inc.php
share/mantis/library/adodb/drivers/adodb-oci8po.inc.php
share/mantis/library/adodb/drivers/adodb-odbc.inc.php
share/mantis/library/adodb/drivers/adodb-odbc_db2.inc.php
share/mantis/library/adodb/drivers/adodb-odbc_mssql.inc.php
share/mantis/library/adodb/drivers/adodb-odbc_oracle.inc.php
share/mantis/library/adodb/drivers/adodb-odbtp.inc.php
share/mantis/library/adodb/drivers/adodb-odbtp_unicode.inc.php
share/mantis/library/adodb/drivers/adodb-oracle.inc.php
share/mantis/library/adodb/drivers/adodb-pdo.inc.php
share/mantis/library/adodb/drivers/adodb-pdo_mssql.inc.php
share/mantis/library/adodb/drivers/adodb-pdo_mysql.inc.php
share/mantis/library/adodb/drivers/adodb-pdo_oci.inc.php
share/mantis/library/adodb/drivers/adodb-pdo_pgsql.inc.php
share/mantis/library/adodb/drivers/adodb-pdo_sqlite.inc.php
share/mantis/library/adodb/drivers/adodb-postgres.inc.php
share/mantis/library/adodb/drivers/adodb-postgres64.inc.php
share/mantis/library/adodb/drivers/adodb-postgres7.inc.php
share/mantis/library/adodb/drivers/adodb-postgres8.inc.php
share/mantis/library/adodb/drivers/adodb-proxy.inc.php
share/mantis/library/adodb/drivers/adodb-sapdb.inc.php
share/mantis/library/adodb/drivers/adodb-sqlanywhere.inc.php
share/mantis/library/adodb/drivers/adodb-sqlite.inc.php
share/mantis/library/adodb/drivers/adodb-sqlitepo.inc.php
share/mantis/library/adodb/drivers/adodb-sybase.inc.php
share/mantis/library/adodb/drivers/adodb-sybase_ase.inc.php
share/mantis/library/adodb/drivers/adodb-vfp.inc.php
share/mantis/library/adodb/index.html
share/mantis/library/adodb/lang/adodb-ar.inc.php
share/mantis/library/adodb/lang/adodb-bg.inc.php
share/mantis/library/adodb/lang/adodb-bgutf8.inc.php
share/mantis/library/adodb/lang/adodb-ca.inc.php
share/mantis/library/adodb/lang/adodb-cn.inc.php
share/mantis/library/adodb/lang/adodb-cz.inc.php
share/mantis/library/adodb/lang/adodb-da.inc.php
share/mantis/library/adodb/lang/adodb-de.inc.php
share/mantis/library/adodb/lang/adodb-en.inc.php
share/mantis/library/adodb/lang/adodb-es.inc.php
share/mantis/library/adodb/lang/adodb-esperanto.inc.php
share/mantis/library/adodb/lang/adodb-fa.inc.php
share/mantis/library/adodb/lang/adodb-fr.inc.php
share/mantis/library/adodb/lang/adodb-hu.inc.php
share/mantis/library/adodb/lang/adodb-it.inc.php
share/mantis/library/adodb/lang/adodb-nl.inc.php
share/mantis/library/adodb/lang/adodb-pl.inc.php
share/mantis/library/adodb/lang/adodb-pt-br.inc.php
share/mantis/library/adodb/lang/adodb-ro.inc.php
share/mantis/library/adodb/lang/adodb-ru1251.inc.php
share/mantis/library/adodb/lang/adodb-sv.inc.php
share/mantis/library/adodb/lang/adodb-uk1251.inc.php
share/mantis/library/adodb/lang/adodb_th.inc.php
share/mantis/library/adodb/license.txt
share/mantis/library/adodb/perf/perf-db2.inc.php
share/mantis/library/adodb/perf/perf-informix.inc.php
share/mantis/library/adodb/perf/perf-mssql.inc.php
share/mantis/library/adodb/perf/perf-mssqlnative.inc.php
share/mantis/library/adodb/perf/perf-mysql.inc.php
share/mantis/library/adodb/perf/perf-oci8.inc.php
share/mantis/library/adodb/perf/perf-postgres.inc.php
share/mantis/library/adodb/pivottable.inc.php
share/mantis/library/adodb/readme.txt
share/mantis/library/adodb/readme_mantis.txt
share/mantis/library/adodb/rsfilter.inc.php
share/mantis/library/adodb/session/adodb-compress-bzip2.php
share/mantis/library/adodb/session/adodb-compress-gzip.php
share/mantis/library/adodb/session/adodb-cryptsession.php
share/mantis/library/adodb/session/adodb-cryptsession2.php
share/mantis/library/adodb/session/adodb-encrypt-mcrypt.php
share/mantis/library/adodb/session/adodb-encrypt-md5.php
share/mantis/library/adodb/session/adodb-encrypt-secret.php
share/mantis/library/adodb/session/adodb-encrypt-sha1.php
share/mantis/library/adodb/session/adodb-sess.txt
share/mantis/library/adodb/session/adodb-session-clob.php
share/mantis/library/adodb/session/adodb-session-clob2.php
share/mantis/library/adodb/session/adodb-session.php
share/mantis/library/adodb/session/adodb-session2.php
share/mantis/library/adodb/session/adodb-sessions.mysql.sql
share/mantis/library/adodb/session/adodb-sessions.oracle.clob.sql
share/mantis/library/adodb/session/adodb-sessions.oracle.sql
share/mantis/library/adodb/session/crypt.inc.php
share/mantis/library/adodb/session/old/adodb-cryptsession.php
share/mantis/library/adodb/session/old/adodb-session-clob.php
share/mantis/library/adodb/session/old/adodb-session.php
share/mantis/library/adodb/session/old/crypt.inc.php
share/mantis/library/adodb/session/session_schema.xml
share/mantis/library/adodb/session/session_schema2.xml
share/mantis/library/adodb/toexport.inc.php
share/mantis/library/adodb/tohtml.inc.php
share/mantis/library/adodb/xmlschema.dtd
share/mantis/library/adodb/xmlschema03.dtd
share/mantis/library/adodb/xsl/convert-0.1-0.2.xsl
share/mantis/library/adodb/xsl/convert-0.1-0.3.xsl
share/mantis/library/adodb/xsl/convert-0.2-0.1.xsl
share/mantis/library/adodb/xsl/convert-0.2-0.3.xsl
share/mantis/library/adodb/xsl/remove-0.2.xsl
share/mantis/library/adodb/xsl/remove-0.3.xsl
share/mantis/library/disposable/changelog.txt
share/mantis/library/disposable/disposable.php
share/mantis/library/disposable/index.html
share/mantis/library/disposable/license.txt
share/mantis/library/disposable/readme.txt
share/mantis/library/disposable/readme_mantis.txt
share/mantis/library/ezc/Base/src/base.php
share/mantis/library/ezc/Base/src/exceptions/autoload.php
share/mantis/library/ezc/Base/src/exceptions/double_class_repository_prefix.php
share/mantis/library/ezc/Base/src/exceptions/exception.php
share/mantis/library/ezc/Base/src/exceptions/extension_not_found.php
share/mantis/library/ezc/Base/src/exceptions/file_exception.php
share/mantis/library/ezc/Base/src/exceptions/file_io.php
share/mantis/library/ezc/Base/src/exceptions/file_not_found.php
share/mantis/library/ezc/Base/src/exceptions/file_permission.php
share/mantis/library/ezc/Base/src/exceptions/functionality_not_supported.php
share/mantis/library/ezc/Base/src/exceptions/init_callback_configured.php
share/mantis/library/ezc/Base/src/exceptions/invalid_callback_class.php
share/mantis/library/ezc/Base/src/exceptions/invalid_parent_class.php
share/mantis/library/ezc/Base/src/exceptions/property_not_found.php
share/mantis/library/ezc/Base/src/exceptions/property_permission.php
share/mantis/library/ezc/Base/src/exceptions/setting_not_found.php
share/mantis/library/ezc/Base/src/exceptions/setting_value.php
share/mantis/library/ezc/Base/src/exceptions/value.php
share/mantis/library/ezc/Base/src/exceptions/whatever.php
share/mantis/library/ezc/Base/src/ezc_bootstrap.php
share/mantis/library/ezc/Base/src/features.php
share/mantis/library/ezc/Base/src/file.php
share/mantis/library/ezc/Base/src/init.php
share/mantis/library/ezc/Base/src/interfaces/configuration_initializer.php
share/mantis/library/ezc/Base/src/interfaces/exportable.php
share/mantis/library/ezc/Base/src/interfaces/persistable.php
share/mantis/library/ezc/Base/src/metadata.php
share/mantis/library/ezc/Base/src/metadata/pear.php
share/mantis/library/ezc/Base/src/metadata/tarball.php
share/mantis/library/ezc/Base/src/options.php
share/mantis/library/ezc/Base/src/options/autoload.php
share/mantis/library/ezc/Base/src/struct.php
share/mantis/library/ezc/Base/src/structs/file_find_context.php
share/mantis/library/ezc/Base/src/structs/repository_directory.php
share/mantis/library/ezc/Graph/src/axis/container.php
share/mantis/library/ezc/Graph/src/axis/date.php
share/mantis/library/ezc/Graph/src/axis/labeled.php
share/mantis/library/ezc/Graph/src/axis/logarithmic.php
share/mantis/library/ezc/Graph/src/axis/numeric.php
share/mantis/library/ezc/Graph/src/charts/bar.php
share/mantis/library/ezc/Graph/src/charts/horizontal_bar.php
share/mantis/library/ezc/Graph/src/charts/line.php
share/mantis/library/ezc/Graph/src/charts/odometer.php
share/mantis/library/ezc/Graph/src/charts/pie.php
share/mantis/library/ezc/Graph/src/charts/radar.php
share/mantis/library/ezc/Graph/src/colors/color.php
share/mantis/library/ezc/Graph/src/colors/linear_gradient.php
share/mantis/library/ezc/Graph/src/colors/radial_gradient.php
share/mantis/library/ezc/Graph/src/data_container/base.php
share/mantis/library/ezc/Graph/src/data_container/single.php
share/mantis/library/ezc/Graph/src/datasets/array.php
share/mantis/library/ezc/Graph/src/datasets/average.php
share/mantis/library/ezc/Graph/src/datasets/base.php
share/mantis/library/ezc/Graph/src/datasets/numeric.php
share/mantis/library/ezc/Graph/src/datasets/property/axis.php
share/mantis/library/ezc/Graph/src/datasets/property/boolean.php
share/mantis/library/ezc/Graph/src/datasets/property/color.php
share/mantis/library/ezc/Graph/src/datasets/property/integer.php
share/mantis/library/ezc/Graph/src/datasets/property/string.php
share/mantis/library/ezc/Graph/src/driver/cairo.php
share/mantis/library/ezc/Graph/src/driver/cairo_oo.php
share/mantis/library/ezc/Graph/src/driver/flash.php
share/mantis/library/ezc/Graph/src/driver/gd.php
share/mantis/library/ezc/Graph/src/driver/svg.php
share/mantis/library/ezc/Graph/src/driver/svg_font.php
share/mantis/library/ezc/Graph/src/driver/verbose.php
share/mantis/library/ezc/Graph/src/element/axis.php
share/mantis/library/ezc/Graph/src/element/background.php
share/mantis/library/ezc/Graph/src/element/legend.php
share/mantis/library/ezc/Graph/src/element/text.php
share/mantis/library/ezc/Graph/src/exceptions/date_parsing.php
share/mantis/library/ezc/Graph/src/exceptions/exception.php
share/mantis/library/ezc/Graph/src/exceptions/flash_bitmap_type.php
share/mantis/library/ezc/Graph/src/exceptions/font_rendering.php
share/mantis/library/ezc/Graph/src/exceptions/font_type.php
share/mantis/library/ezc/Graph/src/exceptions/incompatible_driver.php
share/mantis/library/ezc/Graph/src/exceptions/invalid_assignement.php
share/mantis/library/ezc/Graph/src/exceptions/invalid_data.php
share/mantis/library/ezc/Graph/src/exceptions/invalid_data_source.php
share/mantis/library/ezc/Graph/src/exceptions/invalid_dimensions.php
share/mantis/library/ezc/Graph/src/exceptions/invalid_display_type.php
share/mantis/library/ezc/Graph/src/exceptions/invalid_id.php
share/mantis/library/ezc/Graph/src/exceptions/invalid_image_file.php
share/mantis/library/ezc/Graph/src/exceptions/invalid_keys.php
share/mantis/library/ezc/Graph/src/exceptions/invalid_step_size.php
share/mantis/library/ezc/Graph/src/exceptions/no_data.php
share/mantis/library/ezc/Graph/src/exceptions/no_such_data.php
share/mantis/library/ezc/Graph/src/exceptions/no_such_dataset.php
share/mantis/library/ezc/Graph/src/exceptions/no_such_element.php
share/mantis/library/ezc/Graph/src/exceptions/not_rendered.php
share/mantis/library/ezc/Graph/src/exceptions/out_of_boundings.php
share/mantis/library/ezc/Graph/src/exceptions/out_of_logarithmical_boundings.php
share/mantis/library/ezc/Graph/src/exceptions/reducement_failed.php
share/mantis/library/ezc/Graph/src/exceptions/too_many_datasets.php
share/mantis/library/ezc/Graph/src/exceptions/unknown_color_definition.php
share/mantis/library/ezc/Graph/src/exceptions/unregular_steps.php
share/mantis/library/ezc/Graph/src/exceptions/unsupported_image_type.php
share/mantis/library/ezc/Graph/src/graph.php
share/mantis/library/ezc/Graph/src/interfaces/axis_label_renderer.php
share/mantis/library/ezc/Graph/src/interfaces/chart.php
share/mantis/library/ezc/Graph/src/interfaces/dataset_property.php
share/mantis/library/ezc/Graph/src/interfaces/driver.php
share/mantis/library/ezc/Graph/src/interfaces/element.php
share/mantis/library/ezc/Graph/src/interfaces/horizontal_bar_renderer.php
share/mantis/library/ezc/Graph/src/interfaces/odometer_renderer.php
share/mantis/library/ezc/Graph/src/interfaces/palette.php
share/mantis/library/ezc/Graph/src/interfaces/radar_renderer.php
share/mantis/library/ezc/Graph/src/interfaces/renderer.php
share/mantis/library/ezc/Graph/src/interfaces/stacked_bar_renderer.php
share/mantis/library/ezc/Graph/src/math/boundings.php
share/mantis/library/ezc/Graph/src/math/matrix.php
share/mantis/library/ezc/Graph/src/math/polynom.php
share/mantis/library/ezc/Graph/src/math/rotation.php
share/mantis/library/ezc/Graph/src/math/transformation.php
share/mantis/library/ezc/Graph/src/math/translation.php
share/mantis/library/ezc/Graph/src/math/vector.php
share/mantis/library/ezc/Graph/src/options/cairo_driver.php
share/mantis/library/ezc/Graph/src/options/chart.php
share/mantis/library/ezc/Graph/src/options/driver.php
share/mantis/library/ezc/Graph/src/options/flash_driver.php
share/mantis/library/ezc/Graph/src/options/font.php
share/mantis/library/ezc/Graph/src/options/gd_driver.php
share/mantis/library/ezc/Graph/src/options/line_chart.php
share/mantis/library/ezc/Graph/src/options/odometer_chart.php
share/mantis/library/ezc/Graph/src/options/pie_chart.php
share/mantis/library/ezc/Graph/src/options/radar_chart.php
share/mantis/library/ezc/Graph/src/options/renderer.php
share/mantis/library/ezc/Graph/src/options/renderer_2d.php
share/mantis/library/ezc/Graph/src/options/renderer_3d.php
share/mantis/library/ezc/Graph/src/options/svg_driver.php
share/mantis/library/ezc/Graph/src/palette/black.php
share/mantis/library/ezc/Graph/src/palette/ez.php
share/mantis/library/ezc/Graph/src/palette/ez_blue.php
share/mantis/library/ezc/Graph/src/palette/ez_green.php
share/mantis/library/ezc/Graph/src/palette/ez_red.php
share/mantis/library/ezc/Graph/src/palette/tango.php
share/mantis/library/ezc/Graph/src/renderer/2d.php
share/mantis/library/ezc/Graph/src/renderer/3d.php
share/mantis/library/ezc/Graph/src/renderer/axis_label_boxed.php
share/mantis/library/ezc/Graph/src/renderer/axis_label_centered.php
share/mantis/library/ezc/Graph/src/renderer/axis_label_exact.php
share/mantis/library/ezc/Graph/src/renderer/axis_label_none.php
share/mantis/library/ezc/Graph/src/renderer/axis_label_radar.php
share/mantis/library/ezc/Graph/src/renderer/axis_label_rotated.php
share/mantis/library/ezc/Graph/src/renderer/axis_label_rotated_boxed.php
share/mantis/library/ezc/Graph/src/renderer/horizontal_bar.php
share/mantis/library/ezc/Graph/src/structs/context.php
share/mantis/library/ezc/Graph/src/structs/coordinate.php
share/mantis/library/ezc/Graph/src/structs/step.php
share/mantis/library/ezc/Graph/src/tools.php
share/mantis/library/ezc/autoload/base_autoload.php
share/mantis/library/ezc/autoload/graph_autoload.php
share/mantis/library/nusoap/0001-Fix-12312-NuSOAP-web-description-XSS-vulnerability.patch
share/mantis/library/nusoap/changelog
share/mantis/library/nusoap/class.nusoap_base.php
share/mantis/library/nusoap/class.soap_fault.php
share/mantis/library/nusoap/class.soap_parser.php
share/mantis/library/nusoap/class.soap_server.php
share/mantis/library/nusoap/class.soap_transport_http.php
share/mantis/library/nusoap/class.soap_val.php
share/mantis/library/nusoap/class.soapclient.php
share/mantis/library/nusoap/class.wsdl.php
share/mantis/library/nusoap/class.wsdlcache.php
share/mantis/library/nusoap/class.xmlschema.php
share/mantis/library/nusoap/index.html
share/mantis/library/nusoap/nusoap.php
share/mantis/library/nusoap/nusoapmime.php
share/mantis/library/nusoap/readme_mantis.txt
share/mantis/library/phpmailer/LICENSE
share/mantis/library/phpmailer/README
share/mantis/library/phpmailer/changelog.txt
share/mantis/library/phpmailer/class.phpmailer.php
share/mantis/library/phpmailer/class.pop3.php
share/mantis/library/phpmailer/class.smtp.php
share/mantis/library/phpmailer/index.html
share/mantis/library/phpmailer/language/phpmailer.lang-ar.php
share/mantis/library/phpmailer/language/phpmailer.lang-br.php
share/mantis/library/phpmailer/language/phpmailer.lang-ca.php
share/mantis/library/phpmailer/language/phpmailer.lang-ch.php
share/mantis/library/phpmailer/language/phpmailer.lang-cz.php
share/mantis/library/phpmailer/language/phpmailer.lang-de.php
share/mantis/library/phpmailer/language/phpmailer.lang-dk.php
share/mantis/library/phpmailer/language/phpmailer.lang-es.php
share/mantis/library/phpmailer/language/phpmailer.lang-et.php
share/mantis/library/phpmailer/language/phpmailer.lang-fi.php
share/mantis/library/phpmailer/language/phpmailer.lang-fo.php
share/mantis/library/phpmailer/language/phpmailer.lang-fr.php
share/mantis/library/phpmailer/language/phpmailer.lang-hu.php
share/mantis/library/phpmailer/language/phpmailer.lang-it.php
share/mantis/library/phpmailer/language/phpmailer.lang-ja.php
share/mantis/library/phpmailer/language/phpmailer.lang-nl.php
share/mantis/library/phpmailer/language/phpmailer.lang-no.php
share/mantis/library/phpmailer/language/phpmailer.lang-pl.php
share/mantis/library/phpmailer/language/phpmailer.lang-ro.php
share/mantis/library/phpmailer/language/phpmailer.lang-ru.php
share/mantis/library/phpmailer/language/phpmailer.lang-se.php
share/mantis/library/phpmailer/language/phpmailer.lang-tr.php
share/mantis/library/phpmailer/language/phpmailer.lang-zh.php
share/mantis/library/phpmailer/language/phpmailer.lang-zh_cn.php
share/mantis/library/phpmailer/readme_mantis.txt
share/mantis/library/projax/classes/JavaScript.php
share/mantis/library/projax/classes/Prototype.php
share/mantis/library/projax/classes/Scriptaculous.php
share/mantis/library/projax/index.html
share/mantis/library/projax/projax.php
share/mantis/library/projax/readme_mantis.txt
share/mantis/library/rssbuilder/class.ObjectIterator.inc.php
share/mantis/library/rssbuilder/class.ObjectList.inc.php
share/mantis/library/rssbuilder/class.RSSBase.inc.php
share/mantis/library/rssbuilder/class.RSSBuilder.inc.php
share/mantis/library/rssbuilder/class.RSSItem.inc.php
share/mantis/library/rssbuilder/class.RSSItemList.inc.php
share/mantis/library/rssbuilder/class.RSS_V_091.inc.php
share/mantis/library/rssbuilder/class.RSS_V_100.inc.php
share/mantis/library/rssbuilder/class.RSS_V_200.inc.php
share/mantis/library/rssbuilder/class.RSS_V_abstract.inc.php
share/mantis/library/rssbuilder/doc/changelog_rssbuilder.htm
share/mantis/library/rssbuilder/doc/doc.css
share/mantis/library/rssbuilder/index.html
share/mantis/library/rssbuilder/interface.RSS.inc.php
share/mantis/library/rssbuilder/readme_mantis.txt
share/mantis/library/rssbuilder/rss_sample_script.php
share/mantis/library/utf8/ChangeLog
share/mantis/library/utf8/LICENSE
share/mantis/library/utf8/README
share/mantis/library/utf8/TODO.tsk
share/mantis/library/utf8/exp/regexunicode.php
share/mantis/library/utf8/index.html
share/mantis/library/utf8/mbstring/core.php
share/mantis/library/utf8/native/core.php
share/mantis/library/utf8/ord.php
share/mantis/library/utf8/readme_mantis.txt
share/mantis/library/utf8/str_ireplace.php
share/mantis/library/utf8/str_pad.php
share/mantis/library/utf8/str_split.php
share/mantis/library/utf8/strcasecmp.php
share/mantis/library/utf8/strcspn.php
share/mantis/library/utf8/stristr.php
share/mantis/library/utf8/strrev.php
share/mantis/library/utf8/strspn.php
share/mantis/library/utf8/substr_replace.php
share/mantis/library/utf8/trim.php
share/mantis/library/utf8/ucfirst.php
share/mantis/library/utf8/ucwords.php
share/mantis/library/utf8/utf8.php
share/mantis/library/utf8/utils/ascii.php
share/mantis/library/utf8/utils/bad.php
share/mantis/library/utf8/utils/patterns.php
share/mantis/library/utf8/utils/position.php
share/mantis/library/utf8/utils/specials.php
share/mantis/library/utf8/utils/unicode.php
share/mantis/library/utf8/utils/validation.php
share/mantis/login.php
2005-10-23 17:37:24 +02:00
share/mantis/login_anon.php
share/mantis/login_cookie_test.php
share/mantis/login_page.php
2005-10-23 17:37:24 +02:00
share/mantis/login_select_proj_page.php
share/mantis/logout_page.php
share/mantis/lost_pwd.php
2005-10-23 17:37:24 +02:00
share/mantis/lost_pwd_page.php
share/mantis/main_page.php
2005-10-23 17:37:24 +02:00
share/mantis/make_captcha_img.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/manage_columns_copy.php
share/mantis/manage_columns_inc.php
share/mantis/manage_config_columns_page.php
share/mantis/manage_config_columns_reset.php
share/mantis/manage_config_columns_set.php
share/mantis/manage_config_email_page.php
share/mantis/manage_config_email_set.php
share/mantis/manage_config_revert.php
2005-10-23 17:37:24 +02:00
share/mantis/manage_config_work_threshold_page.php
share/mantis/manage_config_work_threshold_set.php
share/mantis/manage_config_workflow_page.php
share/mantis/manage_config_workflow_set.php
share/mantis/manage_custom_field_create.php
share/mantis/manage_custom_field_delete.php
share/mantis/manage_custom_field_edit_page.php
share/mantis/manage_custom_field_page.php
share/mantis/manage_custom_field_proj_add.php
share/mantis/manage_custom_field_update.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/manage_overview_page.php
share/mantis/manage_plugin_install.php
share/mantis/manage_plugin_page.php
share/mantis/manage_plugin_uninstall.php
share/mantis/manage_plugin_update.php
share/mantis/manage_plugin_upgrade.php
share/mantis/manage_prof_menu_page.php
share/mantis/manage_proj_cat_add.php
share/mantis/manage_proj_cat_copy.php
share/mantis/manage_proj_cat_delete.php
share/mantis/manage_proj_cat_edit_page.php
share/mantis/manage_proj_cat_update.php
2005-10-23 17:37:24 +02:00
share/mantis/manage_proj_create.php
share/mantis/manage_proj_create_page.php
2005-10-23 17:37:24 +02:00
share/mantis/manage_proj_custom_field_add_existing.php
share/mantis/manage_proj_custom_field_copy.php
2005-10-23 17:37:24 +02:00
share/mantis/manage_proj_custom_field_remove.php
share/mantis/manage_proj_custom_field_update.php
share/mantis/manage_proj_delete.php
share/mantis/manage_proj_edit_page.php
share/mantis/manage_proj_page.php
share/mantis/manage_proj_subproj_add.php
share/mantis/manage_proj_subproj_delete.php
share/mantis/manage_proj_update.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/manage_proj_update_children.php
share/mantis/manage_proj_user_add.php
share/mantis/manage_proj_user_copy.php
share/mantis/manage_proj_user_remove.php
share/mantis/manage_proj_ver_add.php
share/mantis/manage_proj_ver_copy.php
share/mantis/manage_proj_ver_delete.php
share/mantis/manage_proj_ver_edit_page.php
share/mantis/manage_proj_ver_update.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/manage_tags_page.php
share/mantis/manage_user_create.php
share/mantis/manage_user_create_page.php
share/mantis/manage_user_delete.php
share/mantis/manage_user_edit_page.php
share/mantis/manage_user_page.php
share/mantis/manage_user_proj_add.php
share/mantis/manage_user_proj_delete.php
2005-10-23 17:37:24 +02:00
share/mantis/manage_user_prune.php
share/mantis/manage_user_reset.php
share/mantis/manage_user_update.php
2005-10-23 17:37:24 +02:00
share/mantis/meta_inc.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/my_view_inc.php
2005-10-23 17:37:24 +02:00
share/mantis/my_view_page.php
share/mantis/news_add.php
2005-10-23 17:37:24 +02:00
share/mantis/news_edit_page.php
share/mantis/news_list_page.php
share/mantis/news_menu_page.php
share/mantis/news_rss.php
share/mantis/news_update.php
share/mantis/news_view_page.php
share/mantis/permalink_page.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/phing/tasks/mantisbt/ExtractMantisBTVersion.php
share/mantis/plugin.php
share/mantis/plugin_file.php
share/mantis/plugins/MantisCoreFormatting/MantisCoreFormatting.php
share/mantis/plugins/MantisCoreFormatting/lang/strings_afrikaans.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_arabic.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_belarusian_tarask.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_breton.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_bulgarian.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_catalan.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_chinese_simplified.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_chinese_traditional.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_czech.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_dutch.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_english.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_finnish.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_french.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_galician.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_german.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_hebrew.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_hungarian.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_interlingua.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_italian.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_japanese.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_lithuanian.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_macedonian.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_norwegian_bokmal.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_occitan.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_polish.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_portuguese_brazil.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_portuguese_standard.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_qqq.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_ripoarisch.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_romanian.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_russian.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_serbian.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_serbian_latin.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_slovak.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_spanish.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_swedish.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_swissgerman.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_tagalog.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_turkish.txt
share/mantis/plugins/MantisCoreFormatting/lang/strings_vietnamese.txt
share/mantis/plugins/MantisCoreFormatting/pages/config.php
share/mantis/plugins/MantisCoreFormatting/pages/config_edit.php
share/mantis/plugins/MantisGraph/MantisGraph.php
share/mantis/plugins/MantisGraph/core/Period.php
share/mantis/plugins/MantisGraph/core/graph_api.php
share/mantis/plugins/MantisGraph/lang/strings_arabic.txt
share/mantis/plugins/MantisGraph/lang/strings_arabicegyptianspoken.txt
share/mantis/plugins/MantisGraph/lang/strings_belarusian_tarask.txt
share/mantis/plugins/MantisGraph/lang/strings_breton.txt
share/mantis/plugins/MantisGraph/lang/strings_bulgarian.txt
share/mantis/plugins/MantisGraph/lang/strings_catalan.txt
share/mantis/plugins/MantisGraph/lang/strings_chinese_simplified.txt
share/mantis/plugins/MantisGraph/lang/strings_chinese_traditional.txt
share/mantis/plugins/MantisGraph/lang/strings_czech.txt
share/mantis/plugins/MantisGraph/lang/strings_danish.txt
share/mantis/plugins/MantisGraph/lang/strings_dutch.txt
share/mantis/plugins/MantisGraph/lang/strings_english.txt
share/mantis/plugins/MantisGraph/lang/strings_estonian.txt
share/mantis/plugins/MantisGraph/lang/strings_finnish.txt
share/mantis/plugins/MantisGraph/lang/strings_french.txt
share/mantis/plugins/MantisGraph/lang/strings_galician.txt
share/mantis/plugins/MantisGraph/lang/strings_german.txt
share/mantis/plugins/MantisGraph/lang/strings_hebrew.txt
share/mantis/plugins/MantisGraph/lang/strings_hungarian.txt
share/mantis/plugins/MantisGraph/lang/strings_interlingua.txt
share/mantis/plugins/MantisGraph/lang/strings_italian.txt
share/mantis/plugins/MantisGraph/lang/strings_japanese.txt
share/mantis/plugins/MantisGraph/lang/strings_lithuanian.txt
share/mantis/plugins/MantisGraph/lang/strings_macedonian.txt
share/mantis/plugins/MantisGraph/lang/strings_norwegian_bokmal.txt
share/mantis/plugins/MantisGraph/lang/strings_occitan.txt
share/mantis/plugins/MantisGraph/lang/strings_polish.txt
share/mantis/plugins/MantisGraph/lang/strings_portuguese_brazil.txt
share/mantis/plugins/MantisGraph/lang/strings_portuguese_standard.txt
share/mantis/plugins/MantisGraph/lang/strings_qqq.txt
share/mantis/plugins/MantisGraph/lang/strings_ripoarisch.txt
share/mantis/plugins/MantisGraph/lang/strings_romanian.txt
share/mantis/plugins/MantisGraph/lang/strings_russian.txt
share/mantis/plugins/MantisGraph/lang/strings_serbian.txt
share/mantis/plugins/MantisGraph/lang/strings_serbian_latin.txt
share/mantis/plugins/MantisGraph/lang/strings_slovak.txt
share/mantis/plugins/MantisGraph/lang/strings_spanish.txt
share/mantis/plugins/MantisGraph/lang/strings_swedish.txt
share/mantis/plugins/MantisGraph/lang/strings_swissgerman.txt
share/mantis/plugins/MantisGraph/lang/strings_tagalog.txt
share/mantis/plugins/MantisGraph/lang/strings_turkish.txt
share/mantis/plugins/MantisGraph/lang/strings_vietnamese.txt
share/mantis/plugins/MantisGraph/pages/bug_graph_bycategory.php
share/mantis/plugins/MantisGraph/pages/bug_graph_bystatus.php
share/mantis/plugins/MantisGraph/pages/bug_graph_page.php
share/mantis/plugins/MantisGraph/pages/config.php
share/mantis/plugins/MantisGraph/pages/config_edit.php
share/mantis/plugins/MantisGraph/pages/summary_graph_bycategory.php
share/mantis/plugins/MantisGraph/pages/summary_graph_bycategory_pct.php
share/mantis/plugins/MantisGraph/pages/summary_graph_bydeveloper.php
share/mantis/plugins/MantisGraph/pages/summary_graph_bypriority.php
share/mantis/plugins/MantisGraph/pages/summary_graph_bypriority_mix.php
share/mantis/plugins/MantisGraph/pages/summary_graph_bypriority_pct.php
share/mantis/plugins/MantisGraph/pages/summary_graph_byreporter.php
share/mantis/plugins/MantisGraph/pages/summary_graph_byresolution.php
share/mantis/plugins/MantisGraph/pages/summary_graph_byresolution_mix.php
share/mantis/plugins/MantisGraph/pages/summary_graph_byresolution_pct.php
share/mantis/plugins/MantisGraph/pages/summary_graph_byseverity.php
share/mantis/plugins/MantisGraph/pages/summary_graph_byseverity_mix.php
share/mantis/plugins/MantisGraph/pages/summary_graph_byseverity_pct.php
share/mantis/plugins/MantisGraph/pages/summary_graph_bystatus.php
share/mantis/plugins/MantisGraph/pages/summary_graph_bystatus_pct.php
share/mantis/plugins/MantisGraph/pages/summary_graph_cumulative_bydate.php
share/mantis/plugins/MantisGraph/pages/summary_graph_cumulative_bydate2.php
share/mantis/plugins/MantisGraph/pages/summary_graph_imp_category.php
share/mantis/plugins/MantisGraph/pages/summary_graph_imp_priority.php
share/mantis/plugins/MantisGraph/pages/summary_graph_imp_resolution.php
share/mantis/plugins/MantisGraph/pages/summary_graph_imp_severity.php
share/mantis/plugins/MantisGraph/pages/summary_graph_imp_status.php
share/mantis/plugins/MantisGraph/pages/summary_jpgraph_page.php
share/mantis/plugins/XmlImportExport/ImportXml.php
share/mantis/plugins/XmlImportExport/ImportXml/Interface.php
share/mantis/plugins/XmlImportExport/ImportXml/Issue.php
share/mantis/plugins/XmlImportExport/ImportXml/Mapper.php
share/mantis/plugins/XmlImportExport/XmlImportExport.php
share/mantis/plugins/XmlImportExport/lang/strings_afrikaans.txt
share/mantis/plugins/XmlImportExport/lang/strings_arabic.txt
share/mantis/plugins/XmlImportExport/lang/strings_belarusian_tarask.txt
share/mantis/plugins/XmlImportExport/lang/strings_breton.txt
share/mantis/plugins/XmlImportExport/lang/strings_bulgarian.txt
share/mantis/plugins/XmlImportExport/lang/strings_catalan.txt
share/mantis/plugins/XmlImportExport/lang/strings_chinese_simplified.txt
share/mantis/plugins/XmlImportExport/lang/strings_chinese_traditional.txt
share/mantis/plugins/XmlImportExport/lang/strings_czech.txt
share/mantis/plugins/XmlImportExport/lang/strings_dutch.txt
share/mantis/plugins/XmlImportExport/lang/strings_english.txt
share/mantis/plugins/XmlImportExport/lang/strings_finnish.txt
share/mantis/plugins/XmlImportExport/lang/strings_french.txt
share/mantis/plugins/XmlImportExport/lang/strings_galician.txt
share/mantis/plugins/XmlImportExport/lang/strings_german.txt
share/mantis/plugins/XmlImportExport/lang/strings_hebrew.txt
share/mantis/plugins/XmlImportExport/lang/strings_hungarian.txt
share/mantis/plugins/XmlImportExport/lang/strings_interlingua.txt
share/mantis/plugins/XmlImportExport/lang/strings_italian.txt
share/mantis/plugins/XmlImportExport/lang/strings_japanese.txt
share/mantis/plugins/XmlImportExport/lang/strings_lithuanian.txt
share/mantis/plugins/XmlImportExport/lang/strings_macedonian.txt
share/mantis/plugins/XmlImportExport/lang/strings_norwegian_bokmal.txt
share/mantis/plugins/XmlImportExport/lang/strings_occitan.txt
share/mantis/plugins/XmlImportExport/lang/strings_polish.txt
share/mantis/plugins/XmlImportExport/lang/strings_portuguese_brazil.txt
share/mantis/plugins/XmlImportExport/lang/strings_portuguese_standard.txt
share/mantis/plugins/XmlImportExport/lang/strings_ripoarisch.txt
share/mantis/plugins/XmlImportExport/lang/strings_romanian.txt
share/mantis/plugins/XmlImportExport/lang/strings_russian.txt
share/mantis/plugins/XmlImportExport/lang/strings_serbian.txt
share/mantis/plugins/XmlImportExport/lang/strings_serbian_latin.txt
share/mantis/plugins/XmlImportExport/lang/strings_slovak.txt
share/mantis/plugins/XmlImportExport/lang/strings_spanish.txt
share/mantis/plugins/XmlImportExport/lang/strings_swedish.txt
share/mantis/plugins/XmlImportExport/lang/strings_swissgerman.txt
share/mantis/plugins/XmlImportExport/lang/strings_tagalog.txt
share/mantis/plugins/XmlImportExport/lang/strings_turkish.txt
share/mantis/plugins/XmlImportExport/lang/strings_vietnamese.txt
share/mantis/plugins/XmlImportExport/mantis.dtd
share/mantis/plugins/XmlImportExport/pages/export.php
share/mantis/plugins/XmlImportExport/pages/import.php
share/mantis/plugins/XmlImportExport/pages/import_action.php
share/mantis/print_all_bug_options_inc.php
share/mantis/print_all_bug_options_page.php
share/mantis/print_all_bug_options_reset.php
share/mantis/print_all_bug_options_update.php
share/mantis/print_all_bug_page.php
share/mantis/print_all_bug_page_word.php
share/mantis/print_bug_page.php
2005-10-23 17:37:24 +02:00
share/mantis/print_bugnote_inc.php
share/mantis/proj_doc_add.php
share/mantis/proj_doc_add_page.php
share/mantis/proj_doc_delete.php
share/mantis/proj_doc_edit_page.php
share/mantis/proj_doc_page.php
share/mantis/proj_doc_update.php
share/mantis/project_page.php
share/mantis/query_delete.php
share/mantis/query_delete_page.php
share/mantis/query_store.php
share/mantis/query_store_page.php
share/mantis/query_view_page.php
share/mantis/return_dynamic_filters.php
share/mantis/roadmap_page.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/scripts/README
share/mantis/scripts/checkin.php
share/mantis/scripts/send_emails.php
share/mantis/search.php
2005-10-23 17:37:24 +02:00
share/mantis/set_project.php
share/mantis/signup.php
share/mantis/signup_page.php
share/mantis/summary_page.php
share/mantis/tag_attach.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/tag_create.php
share/mantis/tag_delete.php
share/mantis/tag_detach.php
share/mantis/tag_update.php
share/mantis/tag_update_page.php
share/mantis/tag_view_page.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/tests/AllTests.php
share/mantis/tests/Mantis/AllTests.php
share/mantis/tests/Mantis/EnumTest.php
share/mantis/tests/Mantis/StringTest.php
share/mantis/tests/TestConfig.php
share/mantis/tests/bootstrap.php.sample
share/mantis/tests/soap/AllTests.php
share/mantis/tests/soap/AttachmentTest.php
share/mantis/tests/soap/CategoryTest.php
share/mantis/tests/soap/CompressionTest.php
share/mantis/tests/soap/EnumTest.php
share/mantis/tests/soap/FilterTest.php
share/mantis/tests/soap/IssueAddTest.php
share/mantis/tests/soap/IssueMonitorTest.php
share/mantis/tests/soap/IssueNoteTest.php
share/mantis/tests/soap/IssueUpdateTest.php
share/mantis/tests/soap/LoginTest.php
share/mantis/tests/soap/ProjectTest.php
share/mantis/tests/soap/RelationshipTest.php
share/mantis/tests/soap/SoapBase.php
share/mantis/tests/soap/TagTest.php
share/mantis/tests/soap/UserTest.php
share/mantis/tests/soap/VersionTest.php
share/mantis/tests/test.php
share/mantis/tests/test_config_get_set.php
2005-10-23 17:37:24 +02:00
share/mantis/verify.php
share/mantis/view.php
share/mantis/view_all_bug_page.php
share/mantis/view_all_inc.php
share/mantis/view_all_set.php
2005-10-23 17:37:24 +02:00
share/mantis/view_filters_page.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
share/mantis/view_user_page.php
share/mantis/wiki.php
share/mantis/xmlhttprequest.php
Update to 1.2.12 from 1.1.7 * Set LICENSE and pkglint * Change to 1.2.x branch * Many security fixes shall be included, but I cannot specify them... Changelog: Full log: http://www.mantisbt.org/bugs/changelog_page.php MantisBT Release Notes 1.2.12 Maintenance Release (2012-11-10) ------------------------------------------------- MantisBT 1.2.12 resolves over 70 issues mainly in the following categories: security, MS SQL and PostgreSQL databases support, Change Log page, custom fields, installation, attachments, SOAP API, XML import/export plugin, e-mail (including update of the PHPMailer library to version 5.2.1) and others. In addition, it also brings several enhancements: - filter page now allows 'OR' logic and to query by notes' authors - improved e-mail logging (see #14630) - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event - updated Admin Guide - translations in many languages All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.11 Maintenance Release (2012-06-08) ------------------------------------------------- MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x or older version are advised to upgrade to this release. This release also contains numerous minor bug fixes to MantisBT, SOAP API fixes, enhancements to the admin guide and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.10 Maintenance Release (2012-04-01) ------------------------------------------------- MantisBT 1.2.10 is a maintenance release. All installations that are currently running any 1.2.x version are advised to upgrade to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.9 Maintenance Release (2012-03-03) ------------------------------------------------- MantisBT 1.2.9 release delivers 92 fixes and improvements including security fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API improvements, and others. We recommend that all instances be upgraded to this release. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.8 Security Release (2011-09-05) ------------------------------------------------- MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul Richards discovered 3 vulnerabilities: - 1x local file inclusion (LFI)/directory traversal - 2x cross site scriptin (XSS) These vulnerabilities could have very severe consequences for users of MantisBT, particularly as a result of the local file inclusion vulnerability. If an attacker can upload their own PHP script to the server as an attachment, they may be able to execute this script using the LFI vulnerability. Refer to issues #13191 and #13281 for detailed information. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.7 Security Release (2011-08-19) ------------------------------------------------- MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue in search.php. All MantisBT users (including anonymous users that are not logged in to public bug trackers) could be impacted by this vulnerability. Refer to issue #13245 for full details. This release also contains numerous minor bug fixes to MantisBT and improved translations in many languages. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.6 Maintenance Release (2011-07-26) ------------------------------------------------- MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings bug fixes and improvements across a range of MantisBT features, especially the SOAP API, authentication, time tracking, and billing areas. Documentation and translation updates are also included. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.5 Maintenance Release (2011-04-05) ------------------------------------------------- MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is recommended that all MantisBT users (including those still using 1.1.x or earlier versions) upgrade to this latest release. This release brings improved translations in many languages as well as numerous bug fixes across a range of MantisBT features. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.4 Security Release (2010-12-15) ------------------------------------------------- MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the admin/upgrade_unattended.php script. Issue #12607 provides more detail on the vulnerabilities discovered. We thank Gjoko for his detailed assistance with testing, patching and answering questions. Please note that the /admin/ directory should be removed from all MantisBT installations after the installation or upgrade has been completed. This is particularly true for MantisBT installations accessible over the Internet. Also included with 1.2.4 are some bug fixes relating to fonts in the MantisGraph plugin, SOAP API, CSV export, custom field values, relationship graphs, fields on the manage user page, built-in time tracking and the allow_reporter_close feature. This release includes updated translations for many languages and improved installation documentation in doc/INSTALL. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.3 Security Release (2010-09-14) ------------------------------------------------- MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library. The fix has been applied to the library included in MantisBT releases, and a patch has been submitted upstream for future releases of NuSOAP. See http://www.mantisbt.org/bugs/view.php?id=12312 for further details. Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved excel export, translation updates, and bug fixes to the SOAP API, installation, plugin system, and email notifications. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.2 Security Release (2010-07-29) ------------------------------------------------- MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All installations that are currently running any 1.2.x version are advised to upgrade to this release. Issue #11952 covers a security fix to the display of inline attachments, where "Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks". See http://www.mantisbt.org/bugs/view.php?id=11952 for further details and information. Also included with 1.2.2 are a range of translation updates, regression fixes, and bug fixes, including multiple SOAP API-related bugs and regressions. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.1 Maintenance Release (2010-04-23) ------------------------------------------------- MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All installations that are currently running any 1.1.x or 1.2.0 version are advised to upgrade to this release. Included with 1.2.1 are a range of bug fixes, translation updates, and general improvements over the initial 1.2.0 release. Highlights include an improved installation, a fixed upgrade path from 1.1.x, fixes to the URL and path detection, and updates to the plugin event system. A full changelog for the 1.2.x series can be found on the official site. [1] 1.2.0 Stable Release (2010-02-22) ------------------------------------------------- This release marks the first official release in the 1.2.x series of MantisBT. 1.2.0 is a major feature release for MantisBT, and includes many bugfixes and enhancements over the 1.1.x stable branch. All users of 1.1.x are highly encouraged to upgrade as soon as possible. There are many new features added to 1.2.0, including: - Converted the MantisBT Manual to Docbook format, and added a new Developer's Guide manual, both of which are compiled and included in every release - Implemented a plugin system with many plugins already released [2] - Global categories available to all projects, as well as project categories inheriting from parent projects to child projects; both are optional - Tracked change history for textarea fields (Description, etc) and bug notes - Customizable sets of columns for View Issues page and export formats - Combined simple and advanced views into a single, configurable view that allows selecting exactly what fields to show or hide - Improved roadmap and changelog pages, including version release dates, and permalinks to individual versions - Marking versions as obsolete to hide them from the roadmap and changelog - More configuration options for rebranding MantisBT installations - Improved support for PostgreSQL databases - Improved support for UTF-8 localizations and content - Implemented custom search providers for Firefox and Internet Explorer - Implemented localized timestamps using according to user-preferred timezones There have also been many improvements to the codebase beyond adding features: - Migrated to parameterised database queries throughout the codebase for both performance and security improvements - Added PHPDoc compatible documentation to all internal API's - Removed many hardcoded references to access levels and other enumerations, for improved customizability. - Migrated away from DATETIME fields to integer timestamps for timezone usage - All 3rd party code is now contained within the library/ path, including documentation on library versions and any patches applied - Initial support for MySQL 6 and PHP 5.3
2012-12-25 22:49:05 +01:00
@pkgdir share/mantis/docbook/developers/en/build
@pkgdir share/mantis/docbook/administration_guide/en/build