diff --git a/CHANGELOG b/CHANGELOG index 093a4d4f8..28792d2d2 100644 --- a/CHANGELOG +++ b/CHANGELOG @@ -72,3 +72,4 @@ Added support for Slam64 Linux. ---- Changes since 1.340 ---- Added Redhat Enterprise release 5 support. Requests to the /unauthenticated URL can never execute CGI programs, to provide an extra layer of security against URL escaping attacks. +Fixed XSS bugs in pam_login.cgi. diff --git a/pam_login.cgi b/pam_login.cgi index 4dd79faf9..367009bf2 100755 --- a/pam_login.cgi +++ b/pam_login.cgi @@ -41,7 +41,7 @@ elsif ($in{'timed_out'}) { print "$text{'pam_prefix'}\n"; print "