diff -up cups-1.3.7/cgi-bin/admin.c.CVE-2010-0540 cups-1.3.7/cgi-bin/admin.c --- cups-1.3.7/cgi-bin/admin.c.CVE-2010-0540 2010-05-28 12:13:50.809137719 +0100 +++ cups-1.3.7/cgi-bin/admin.c 2010-05-28 12:13:50.865137281 +0100 @@ -3,7 +3,7 @@ * * Administration CGI for the Common UNIX Printing System (CUPS). * - * Copyright 2007-2008 by Apple Inc. + * Copyright 2007-2010 by Apple Inc. * Copyright 1997-2007 by Easy Software Products. * * These coded instructions, statements, and computer programs are the @@ -110,7 +110,7 @@ main(int argc, /* I - Number of comm * See if we have form data... */ - if (!cgiInitialize()) + if (!cgiInitialize() || !cgiGetVariable("OP")) { /* * Nope, send the administration menu... diff -up cups-1.3.7/cgi-bin/cgi.h.CVE-2010-0540 cups-1.3.7/cgi-bin/cgi.h --- cups-1.3.7/cgi-bin/cgi.h.CVE-2010-0540 2010-05-28 12:13:50.810137931 +0100 +++ cups-1.3.7/cgi-bin/cgi.h 2010-05-28 12:13:50.865137281 +0100 @@ -3,7 +3,7 @@ * * CGI support library definitions. * - * Copyright 2007 by Apple Inc. + * Copyright 2007-2010 by Apple Inc. * Copyright 1997-2006 by Easy Software Products. * * These coded instructions, statements, and computer programs are the @@ -64,7 +64,7 @@ extern char *cgiFormEncode(char *dst, c extern void cgiFreeSearch(void *search); extern const char *cgiGetArray(const char *name, int element); extern void cgiGetAttributes(ipp_t *request, const char *tmpl); -extern char *cgiGetCookie(const char *name, char *buf, int buflen); +extern const char *cgiGetCookie(const char *name); extern const cgi_file_t *cgiGetFile(void); extern cups_array_t *cgiGetIPPObjects(ipp_t *response, void *search); extern int cgiGetSize(const char *name); diff -up cups-1.3.7/cgi-bin/ipp-var.c.CVE-2010-0540 cups-1.3.7/cgi-bin/ipp-var.c --- cups-1.3.7/cgi-bin/ipp-var.c.CVE-2010-0540 2010-05-28 12:13:50.815136425 +0100 +++ cups-1.3.7/cgi-bin/ipp-var.c 2010-05-28 12:13:50.874137407 +0100 @@ -113,7 +113,7 @@ cgiGetAttributes(ipp_t *request, /* */ for (nameptr = name; (ch = getc(in)) != EOF;) - if (strchr("}]<>=! \t\n", ch)) + if (strchr("}]<>=!~ \t\n", ch)) break; else if (nameptr > name && ch == '?') break; diff -up cups-1.3.7/cgi-bin/template.c.CVE-2010-0540 cups-1.3.7/cgi-bin/template.c --- cups-1.3.7/cgi-bin/template.c.CVE-2010-0540 2010-05-28 12:13:50.821137982 +0100 +++ cups-1.3.7/cgi-bin/template.c 2010-05-28 12:13:50.876138501 +0100 @@ -257,7 +257,7 @@ cgi_copy(FILE *out, /* I - Output file uriencode = 0; for (s = name; (ch = getc(in)) != EOF;) - if (strchr("}]<>=! \t\n", ch)) + if (strchr("}]<>=!~ \t\n", ch)) break; else if (s == name && ch == '%') uriencode = 1; @@ -367,6 +367,20 @@ cgi_copy(FILE *out, /* I - Output file continue; } + else if (name[0] == '$') + { + /* + * Insert cookie value or nothing if not defined. + */ + + if ((value = cgiGetCookie(name + 1)) != NULL) + outptr = value; + else + { + outval[0] = '\0'; + outptr = outval; + } + } else { /* @@ -434,7 +448,14 @@ cgi_copy(FILE *out, /* I - Output file * Test for existance... */ - result = cgiGetArray(name, element) != NULL && outptr[0]; + if (name[0] == '?') + result = cgiGetArray(name + 1, element) != NULL; + else if (name[0] == '#') + result = cgiGetVariable(name + 1) != NULL; + else + result = cgiGetArray(name, element) != NULL; + + result = result && outptr[0]; compare[0] = '\0'; } else diff -up cups-1.3.7/cgi-bin/var.c.CVE-2010-0540 cups-1.3.7/cgi-bin/var.c --- cups-1.3.7/cgi-bin/var.c.CVE-2010-0540 2010-05-28 12:13:50.823138800 +0100 +++ cups-1.3.7/cgi-bin/var.c 2010-05-28 12:14:27.348011591 +0100 @@ -3,7 +3,7 @@ * * CGI form variable and array functions. * - * Copyright 2007-2008 by Apple Inc. + * Copyright 2007-2010 by Apple Inc. * Copyright 1997-2005 by Easy Software Products. * * These coded instructions, statements, and computer programs are the @@ -40,6 +40,14 @@ /*#define DEBUG*/ #include "cgi-private.h" #include <errno.h> +#include <cups/md5.h> + + +/* + * Session ID name + */ + +#define CUPS_SID "org.cups.sid" /* @@ -59,6 +67,8 @@ typedef struct /**** Form variable st * Local globals... */ +static int num_cookies = 0;/* Number of cookies */ +static cups_option_t *cookies = NULL;/* Cookies */ static int form_count = 0, /* Form variable count */ form_alloc = 0; /* Number of variables allocated */ static _cgi_var_t *form_vars = NULL; @@ -76,11 +86,13 @@ static void cgi_add_variable(const char static int cgi_compare_variables(const _cgi_var_t *v1, const _cgi_var_t *v2); static _cgi_var_t *cgi_find_variable(const char *name); +static void cgi_initialize_cookies(void); static int cgi_initialize_get(void); static int cgi_initialize_multipart(const char *boundary); static int cgi_initialize_post(void); static int cgi_initialize_string(const char *data); static const char *cgi_passwd(const char *prompt); +static const char *cgi_set_sid(void); static void cgi_sort_variables(void); static void cgi_unlink_file(void); @@ -185,6 +197,17 @@ cgiGetArray(const char *name, /* I - Na /* + * 'cgiGetCookie()' - Get a cookie value. + */ + +const char * /* O - Value or NULL */ +cgiGetCookie(const char *name) /* I - Name of cookie */ +{ + return (cupsGetOption(name, num_cookies, cookies)); +} + + +/* * 'cgiGetFile()' - Get the file (if any) that was submitted in the form. */ @@ -248,6 +271,8 @@ cgiInitialize(void) { const char *method; /* Form posting method */ const char *content_type; /* Content-Type of post data */ + const char *cups_sid_cookie, /* SID cookie */ + *cups_sid_form; /* SID form variable */ /* @@ -272,6 +297,20 @@ cgiInitialize(void) #endif /* DEBUG */ /* + * Get cookies... + */ + + cgi_initialize_cookies(); + + if ((cups_sid_cookie = cgiGetCookie(CUPS_SID)) == NULL) + { + fputs("DEBUG: " CUPS_SID " cookie not found, initializing!\n", stderr); + cups_sid_cookie = cgi_set_sid(); + } + + fprintf(stderr, "DEBUG: " CUPS_SID " cookie is \"%s\"\n", cups_sid_cookie); + + /* * Get the request method (GET or POST)... */ @@ -294,9 +333,27 @@ cgiInitialize(void) boundary += 9; if (content_type && !strncmp(content_type, "multipart/form-data; ", 21)) - return (cgi_initialize_multipart(boundary)); + { + if (!cgi_initialize_multipart(boundary)) + return (0); + } + else if (!cgi_initialize_post()) + return (0); + + if ((cups_sid_form = cgiGetVariable(CUPS_SID)) == NULL || + strcmp(cups_sid_cookie, cups_sid_form)) + { + if (cups_sid_form) + fprintf(stderr, "DEBUG: " CUPS_SID " form variable is \"%s\"\n", + cups_sid_form); + else + fputs("DEBUG: " CUPS_SID " form variable is not present.\n", stderr); + + cgiClearVariables(); + return (0); + } else - return (cgi_initialize_post()); + return (1); } else return (0); @@ -375,6 +432,38 @@ cgiSetArray(const char *name, /* I - Na /* + * 'cgiSetCookie()' - Set a cookie value. + */ + +void +cgiSetCookie(const char *name, /* I - Name */ + const char *value, /* I - Value */ + const char *path, /* I - Path (typically "/") */ + const char *domain, /* I - Domain name */ + time_t expires, /* I - Expiration date (0 for session) */ + int secure) /* I - Require SSL */ +{ + num_cookies = cupsAddOption(name, value, num_cookies, &cookies); + + printf("Set-Cookie: %s=%s", name, value); + if (path) + printf("; path=%s", path); + if (domain) + printf("; domain=%s", domain); + if (expires) + { + char date[256]; /* Date string */ + + printf("; expires=%s", httpGetDateString2(expires, date, sizeof(date))); + } + if (secure) + puts("; secure;"); + else + puts(";"); +} + + +/* * 'cgiSetSize()' - Set the array size. */ @@ -539,6 +628,96 @@ cgi_find_variable(const char *name) /* I /* + * 'cgi_initialize_cookies()' - Initialize cookies. + */ + +static void +cgi_initialize_cookies(void) +{ + const char *cookie; /* HTTP_COOKIE environment variable */ + char name[128], /* Name string */ + value[512], /* Value string */ + *ptr; /* Pointer into name/value */ + + + if ((cookie = getenv("HTTP_COOKIE")) == NULL) + { + fputs("DEBUG: HTTP_COOKIE not defined.\n", stderr); + return; + } + + fprintf(stderr, "DEBUG: HTTP_COOKIE=\"%s\"\n", cookie); + + while (*cookie) + { + /* + * Skip leading whitespace... + */ + + while (isspace(*cookie & 255)) + cookie ++; + if (!*cookie) + break; + + /* + * Copy the name... + */ + + for (ptr = name; *cookie && *cookie != '=';) + if (ptr < (name + sizeof(name) - 1)) + *ptr++ = *cookie++; + else + break; + + if (*cookie != '=') + break; + + *ptr = '\0'; + cookie ++; + + /* + * Then the value... + */ + + if (*cookie == '\"') + { + for (cookie ++, ptr = value; *cookie && *cookie != '\"';) + if (ptr < (value + sizeof(value) - 1)) + *ptr++ = *cookie++; + else + break; + + if (*cookie == '\"') + cookie ++; + } + else + { + for (ptr = value; *cookie && *cookie != ';';) + if (ptr < (value + sizeof(value) - 1)) + *ptr++ = *cookie++; + else + break; + } + + if (*cookie == ';') + cookie ++; + else if (*cookie) + break; + + *ptr = '\0'; + + /* + * Then add the cookie to an array as long as the name doesn't start with + * "$"... + */ + + if (name[0] != '$') + num_cookies = cupsAddOption(name, value, num_cookies, &cookies); + } +} + + +/* * 'cgi_initialize_get()' - Initialize form variables using the GET method. */ @@ -1012,6 +1191,46 @@ cgi_passwd(const char *prompt) /* I - P /* + * 'cgi_set_sid()' - Set the CUPS session ID. + */ + +static const char * /* O - New session ID */ +cgi_set_sid(void) +{ + char buffer[512], /* SID data */ + sid[33]; /* SID string */ + _cups_md5_state_t md5; /* MD5 state */ + unsigned char sum[16]; /* MD5 sum */ + const char *remote_addr, /* REMOTE_ADDR */ + *server_name, /* SERVER_NAME */ + *server_port; /* SERVER_PORT */ + + + if ((remote_addr = getenv("REMOTE_ADDR")) == NULL) + remote_addr = "REMOTE_ADDR"; + if ((server_name = getenv("SERVER_NAME")) == NULL) + server_name = "SERVER_NAME"; + if ((server_port = getenv("SERVER_PORT")) == NULL) + server_port = "SERVER_PORT"; + + srand(time(NULL)); + snprintf(buffer, sizeof(buffer), "%s:%s:%s:%02X%02X%02X%02X%02X%02X%02X%02X", + remote_addr, server_name, server_port, + (unsigned)rand() & 255, (unsigned)rand() & 255, + (unsigned)rand() & 255, (unsigned)rand() & 255, + (unsigned)rand() & 255, (unsigned)rand() & 255, + (unsigned)rand() & 255, (unsigned)rand() & 255); + _cupsMD5Init(&md5); + _cupsMD5Append(&md5, (unsigned char *)buffer, (int)strlen(buffer)); + _cupsMD5Finish(&md5, sum); + + cgiSetCookie(CUPS_SID, httpMD5String(sum, sid), "/", NULL, 0, 0); + + return (cupsGetOption(CUPS_SID, num_cookies, cookies)); +} + + +/* * 'cgi_sort_variables()' - Sort all form variables for faster lookup. */ diff -up cups-1.3.7/scheduler/client.c.CVE-2010-0540 cups-1.3.7/scheduler/client.c --- cups-1.3.7/scheduler/client.c.CVE-2010-0540 2010-05-28 12:13:50.740136626 +0100 +++ cups-1.3.7/scheduler/client.c 2010-05-28 12:13:50.895137621 +0100 @@ -445,14 +445,26 @@ cupsdAcceptClient(cupsd_listener_t *lis) #ifdef AF_INET6 if (temp.addr.sa_family == AF_INET6) { - httpAddrLookup(&temp, con->servername, sizeof(con->servername)); + if (httpAddrLocalhost(&temp)) + strlcpy(con->servername, "localhost", sizeof(con->servername)); + else if (HostNameLookups) + httpAddrLookup(&temp, con->servername, sizeof(con->servername)); + else + httpAddrString(&temp, con->servername, sizeof(con->servername)); + con->serverport = ntohs(lis->address.ipv6.sin6_port); } else #endif /* AF_INET6 */ if (temp.addr.sa_family == AF_INET) { - httpAddrLookup(&temp, con->servername, sizeof(con->servername)); + if (httpAddrLocalhost(&temp)) + strlcpy(con->servername, "localhost", sizeof(con->servername)); + else if (HostNameLookups) + httpAddrLookup(&temp, con->servername, sizeof(con->servername)); + else + httpAddrString(&temp, con->servername, sizeof(con->servername)); + con->serverport = ntohs(lis->address.ipv4.sin_port); } else diff -up cups-1.3.7/templates/add-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/add-class.tmpl --- cups-1.3.7/templates/add-class.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/add-class.tmpl 2010-05-28 12:13:50.897139476 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">Add Class</H2> diff -up cups-1.3.7/templates/add-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/add-printer.tmpl --- cups-1.3.7/templates/add-printer.tmpl.CVE-2010-0540 2007-02-10 19:37:59.000000000 +0000 +++ cups-1.3.7/templates/add-printer.tmpl 2010-05-28 12:13:50.897139476 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {device_uri?<INPUT TYPE="HIDDEN" NAME="DEVICE_URI" VALUE="{device_uri}">:} diff -up cups-1.3.7/templates/add-rss-subscription.tmpl.CVE-2010-0540 cups-1.3.7/templates/add-rss-subscription.tmpl --- cups-1.3.7/templates/add-rss-subscription.tmpl.CVE-2010-0540 2007-02-22 22:06:23.000000000 +0000 +++ cups-1.3.7/templates/add-rss-subscription.tmpl 2010-05-28 12:13:50.898138349 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="add-rss-subscription"> <H2 CLASS="title">Add RSS Subscription</H2> diff -up cups-1.3.7/templates/admin.tmpl.CVE-2010-0540 cups-1.3.7/templates/admin.tmpl --- cups-1.3.7/templates/admin.tmpl.CVE-2010-0540 2007-07-26 19:09:46.000000000 +0100 +++ cups-1.3.7/templates/admin.tmpl 2010-05-28 12:13:50.899138465 +0100 @@ -55,6 +55,7 @@ CLASS="button"></A> <BLOCKQUOTE>{SETTINGS_ERROR}</BLOCKQUOTE>: <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <P><B>Basic Server Settings:</B></P> diff -up cups-1.3.7/templates/choose-device.tmpl.CVE-2010-0540 cups-1.3.7/templates/choose-device.tmpl --- cups-1.3.7/templates/choose-device.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/choose-device.tmpl 2010-05-28 12:13:50.899138465 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/choose-make.tmpl.CVE-2010-0540 cups-1.3.7/templates/choose-make.tmpl --- cups-1.3.7/templates/choose-make.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/choose-make.tmpl 2010-05-28 12:13:50.900136731 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/choose-model.tmpl.CVE-2010-0540 cups-1.3.7/templates/choose-model.tmpl --- cups-1.3.7/templates/choose-model.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/choose-model.tmpl 2010-05-28 12:13:50.901137233 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/choose-serial.tmpl.CVE-2010-0540 cups-1.3.7/templates/choose-serial.tmpl --- cups-1.3.7/templates/choose-serial.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/choose-serial.tmpl 2010-05-28 12:13:50.902137163 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/choose-uri.tmpl.CVE-2010-0540 cups-1.3.7/templates/choose-uri.tmpl --- cups-1.3.7/templates/choose-uri.tmpl.CVE-2010-0540 2006-03-18 12:56:48.000000000 +0000 +++ cups-1.3.7/templates/choose-uri.tmpl 2010-05-28 12:13:50.902137163 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/de/add-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/de/add-class.tmpl --- cups-1.3.7/templates/de/add-class.tmpl.CVE-2010-0540 2006-07-18 14:44:07.000000000 +0100 +++ cups-1.3.7/templates/de/add-class.tmpl 2010-05-28 12:13:50.903136998 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">Klasse hinzufügen</H2> diff -up cups-1.3.7/templates/de/add-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/de/add-printer.tmpl --- cups-1.3.7/templates/de/add-printer.tmpl.CVE-2010-0540 2007-02-10 19:37:59.000000000 +0000 +++ cups-1.3.7/templates/de/add-printer.tmpl 2010-05-28 12:13:50.904012138 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {device_uri?<INPUT TYPE="HIDDEN" NAME="DEVICE_URI" VALUE="{device_uri}">:} diff -up cups-1.3.7/templates/de/add-rss-subscription.tmpl.CVE-2010-0540 cups-1.3.7/templates/de/add-rss-subscription.tmpl --- cups-1.3.7/templates/de/add-rss-subscription.tmpl.CVE-2010-0540 2007-07-27 22:19:56.000000000 +0100 +++ cups-1.3.7/templates/de/add-rss-subscription.tmpl 2010-05-28 12:13:50.904012138 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="add-rss-subscription"> <H2 CLASS="title">RSS Subskription hinzufügen</H2> diff -up cups-1.3.7/templates/de/admin.tmpl.CVE-2010-0540 cups-1.3.7/templates/de/admin.tmpl --- cups-1.3.7/templates/de/admin.tmpl.CVE-2010-0540 2007-08-15 20:33:36.000000000 +0100 +++ cups-1.3.7/templates/de/admin.tmpl 2010-05-28 12:13:50.905012289 +0100 @@ -55,6 +55,7 @@ CLASS="button"></A> <BLOCKQUOTE>{SETTINGS_ERROR}</BLOCKQUOTE>: <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <P><B>Grundlegende Servereinstellungen:</B></P> diff -up cups-1.3.7/templates/de/choose-device.tmpl.CVE-2010-0540 cups-1.3.7/templates/de/choose-device.tmpl --- cups-1.3.7/templates/de/choose-device.tmpl.CVE-2010-0540 2006-07-18 14:44:07.000000000 +0100 +++ cups-1.3.7/templates/de/choose-device.tmpl 2010-05-28 12:13:50.905012289 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/de/choose-make.tmpl.CVE-2010-0540 cups-1.3.7/templates/de/choose-make.tmpl --- cups-1.3.7/templates/de/choose-make.tmpl.CVE-2010-0540 2006-07-18 14:44:07.000000000 +0100 +++ cups-1.3.7/templates/de/choose-make.tmpl 2010-05-28 12:13:50.906012335 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/de/choose-model.tmpl.CVE-2010-0540 cups-1.3.7/templates/de/choose-model.tmpl --- cups-1.3.7/templates/de/choose-model.tmpl.CVE-2010-0540 2006-07-18 14:44:07.000000000 +0100 +++ cups-1.3.7/templates/de/choose-model.tmpl 2010-05-28 12:13:50.907012105 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/de/choose-serial.tmpl.CVE-2010-0540 cups-1.3.7/templates/de/choose-serial.tmpl --- cups-1.3.7/templates/de/choose-serial.tmpl.CVE-2010-0540 2006-07-18 14:44:07.000000000 +0100 +++ cups-1.3.7/templates/de/choose-serial.tmpl 2010-05-28 12:13:50.908012838 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/de/choose-uri.tmpl.CVE-2010-0540 cups-1.3.7/templates/de/choose-uri.tmpl --- cups-1.3.7/templates/de/choose-uri.tmpl.CVE-2010-0540 2006-07-18 14:44:07.000000000 +0100 +++ cups-1.3.7/templates/de/choose-uri.tmpl 2010-05-28 12:13:50.908012838 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/de/edit-config.tmpl.CVE-2010-0540 cups-1.3.7/templates/de/edit-config.tmpl --- cups-1.3.7/templates/de/edit-config.tmpl.CVE-2010-0540 2007-07-25 00:47:12.000000000 +0100 +++ cups-1.3.7/templates/de/edit-config.tmpl 2010-05-28 12:13:50.909012021 +0100 @@ -8,7 +8,7 @@ function reset_config() <H2 CLASS="title">Server Konfigurationsdatei</H2> <FORM NAME="cups" METHOD="POST" ACTION="/admin/"> - +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="config-server"> <TEXTAREA NAME="CUPSDCONF" COLS="80" ROWS="25">{CUPSDCONF}</TEXTAREA> diff -up cups-1.3.7/templates/de/job-move.tmpl.CVE-2010-0540 cups-1.3.7/templates/de/job-move.tmpl --- cups-1.3.7/templates/de/job-move.tmpl.CVE-2010-0540 2006-07-18 14:44:07.000000000 +0100 +++ cups-1.3.7/templates/de/job-move.tmpl 2010-05-28 12:13:50.909012021 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/{SECTION}/{job_id?:{printer_name}}"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {job_id?<INPUT TYPE="HIDDEN" NAME="JOB_ID" VALUE="{job_id}">:} diff -up cups-1.3.7/templates/de/modify-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/de/modify-class.tmpl --- cups-1.3.7/templates/de/modify-class.tmpl.CVE-2010-0540 2006-07-18 14:44:07.000000000 +0100 +++ cups-1.3.7/templates/de/modify-class.tmpl 2010-05-28 12:13:50.910012076 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">Klasse {printer_name} ändern</H2> diff -up cups-1.3.7/templates/de/modify-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/de/modify-printer.tmpl --- cups-1.3.7/templates/de/modify-printer.tmpl.CVE-2010-0540 2006-07-18 14:44:07.000000000 +0100 +++ cups-1.3.7/templates/de/modify-printer.tmpl 2010-05-28 12:13:50.910012076 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {?device_uri=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_DEVICE_URI" VALUE="{device_uri}">} {?printer_make_and_model=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_MAKE_AND_MODEL" VALUE="{printer_make_and_model}">} diff -up cups-1.3.7/templates/de/samba-export.tmpl.CVE-2010-0540 cups-1.3.7/templates/de/samba-export.tmpl --- cups-1.3.7/templates/de/samba-export.tmpl.CVE-2010-0540 2006-07-18 14:44:07.000000000 +0100 +++ cups-1.3.7/templates/de/samba-export.tmpl 2010-05-28 12:13:50.911011621 +0100 @@ -10,6 +10,7 @@ function select_printers() { --></SCRIPT> <FORM METHOD="POST" ACTION="/admin/" NAME="export_samba"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="export-samba"> <H2 CLASS="title">Exportiere Drucker für Samba</H2> diff -up cups-1.3.7/templates/de/set-printer-options-header.tmpl.CVE-2010-0540 cups-1.3.7/templates/de/set-printer-options-header.tmpl --- cups-1.3.7/templates/de/set-printer-options-header.tmpl.CVE-2010-0540 2006-07-18 14:44:07.000000000 +0100 +++ cups-1.3.7/templates/de/set-printer-options-header.tmpl 2010-05-28 12:13:50.911011621 +0100 @@ -1,3 +1,4 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> diff -up cups-1.3.7/templates/de/users.tmpl.CVE-2010-0540 cups-1.3.7/templates/de/users.tmpl --- cups-1.3.7/templates/de/users.tmpl.CVE-2010-0540 2006-07-18 14:44:07.000000000 +0100 +++ cups-1.3.7/templates/de/users.tmpl 2010-05-28 12:13:50.911011621 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{OP}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> {IS_CLASS?<INPUT TYPE="HIDDEN" NAME="IS_CLASS" VALUE="{IS_CLASS}">:} diff -up cups-1.3.7/templates/edit-config.tmpl.CVE-2010-0540 cups-1.3.7/templates/edit-config.tmpl --- cups-1.3.7/templates/edit-config.tmpl.CVE-2010-0540 2007-07-25 00:47:12.000000000 +0100 +++ cups-1.3.7/templates/edit-config.tmpl 2010-05-28 12:13:50.912011687 +0100 @@ -8,7 +8,7 @@ function reset_config() <H2 CLASS="title">Server Configuration File</H2> <FORM NAME="cups" METHOD="POST" ACTION="/admin/"> - +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="config-server"> <TEXTAREA NAME="CUPSDCONF" COLS="80" ROWS="25">{CUPSDCONF}</TEXTAREA> diff -up cups-1.3.7/templates/es/add-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/es/add-class.tmpl --- cups-1.3.7/templates/es/add-class.tmpl.CVE-2010-0540 2006-03-13 13:34:24.000000000 +0000 +++ cups-1.3.7/templates/es/add-class.tmpl 2010-05-28 12:13:50.912011687 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">Añadir clase</H2> diff -up cups-1.3.7/templates/es/add-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/es/add-printer.tmpl --- cups-1.3.7/templates/es/add-printer.tmpl.CVE-2010-0540 2007-02-10 19:37:59.000000000 +0000 +++ cups-1.3.7/templates/es/add-printer.tmpl 2010-05-28 12:13:50.913137110 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {device_uri?<INPUT TYPE="HIDDEN" NAME="DEVICE_URI" VALUE="{device_uri}">:} diff -up cups-1.3.7/templates/es/add-rss-subscription.tmpl.CVE-2010-0540 cups-1.3.7/templates/es/add-rss-subscription.tmpl --- cups-1.3.7/templates/es/add-rss-subscription.tmpl.CVE-2010-0540 2007-08-15 20:33:36.000000000 +0100 +++ cups-1.3.7/templates/es/add-rss-subscription.tmpl 2010-05-28 12:13:50.913137110 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="add-rss-subscription"> <H2 CLASS="title">Añadir subscripción RSS</H2> diff -up cups-1.3.7/templates/es/admin.tmpl.CVE-2010-0540 cups-1.3.7/templates/es/admin.tmpl --- cups-1.3.7/templates/es/admin.tmpl.CVE-2010-0540 2007-08-15 20:33:36.000000000 +0100 +++ cups-1.3.7/templates/es/admin.tmpl 2010-05-28 12:13:50.914137135 +0100 @@ -55,6 +55,7 @@ CLASS="button"></A> <BLOCKQUOTE>{SETTINGS_ERROR}</BLOCKQUOTE>: <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <P><B>Configuración básica del servidor:</B></P> diff -up cups-1.3.7/templates/es/choose-device.tmpl.CVE-2010-0540 cups-1.3.7/templates/es/choose-device.tmpl --- cups-1.3.7/templates/es/choose-device.tmpl.CVE-2010-0540 2006-03-13 13:34:24.000000000 +0000 +++ cups-1.3.7/templates/es/choose-device.tmpl 2010-05-28 12:13:50.914137135 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/es/choose-make.tmpl.CVE-2010-0540 cups-1.3.7/templates/es/choose-make.tmpl --- cups-1.3.7/templates/es/choose-make.tmpl.CVE-2010-0540 2006-03-13 13:34:24.000000000 +0000 +++ cups-1.3.7/templates/es/choose-make.tmpl 2010-05-28 12:13:50.915137226 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/es/choose-model.tmpl.CVE-2010-0540 cups-1.3.7/templates/es/choose-model.tmpl --- cups-1.3.7/templates/es/choose-model.tmpl.CVE-2010-0540 2006-03-13 13:34:24.000000000 +0000 +++ cups-1.3.7/templates/es/choose-model.tmpl 2010-05-28 12:13:50.915137226 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/es/choose-serial.tmpl.CVE-2010-0540 cups-1.3.7/templates/es/choose-serial.tmpl --- cups-1.3.7/templates/es/choose-serial.tmpl.CVE-2010-0540 2006-03-13 13:34:24.000000000 +0000 +++ cups-1.3.7/templates/es/choose-serial.tmpl 2010-05-28 12:13:50.915137226 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/es/choose-uri.tmpl.CVE-2010-0540 cups-1.3.7/templates/es/choose-uri.tmpl --- cups-1.3.7/templates/es/choose-uri.tmpl.CVE-2010-0540 2006-03-18 12:56:48.000000000 +0000 +++ cups-1.3.7/templates/es/choose-uri.tmpl 2010-05-28 12:13:50.916137212 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/es/edit-config.tmpl.CVE-2010-0540 cups-1.3.7/templates/es/edit-config.tmpl --- cups-1.3.7/templates/es/edit-config.tmpl.CVE-2010-0540 2007-07-25 00:47:12.000000000 +0100 +++ cups-1.3.7/templates/es/edit-config.tmpl 2010-05-28 12:13:50.916137212 +0100 @@ -8,7 +8,7 @@ function reset_config() <H2 CLASS="title">Archivo de configuración del servidor</H2> <FORM NAME="cups" METHOD="POST" ACTION="/admin/"> - +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="config-server"> <TEXTAREA NAME="CUPSDCONF" COLS="80" ROWS="25">{CUPSDCONF}</TEXTAREA> diff -up cups-1.3.7/templates/es/job-move.tmpl.CVE-2010-0540 cups-1.3.7/templates/es/job-move.tmpl --- cups-1.3.7/templates/es/job-move.tmpl.CVE-2010-0540 2006-03-13 13:34:24.000000000 +0000 +++ cups-1.3.7/templates/es/job-move.tmpl 2010-05-28 12:13:50.917142154 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/{SECTION}/{job_id?:{printer_name}}"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {job_id?<INPUT TYPE="HIDDEN" NAME="JOB_ID" VALUE="{job_id}">:} diff -up cups-1.3.7/templates/es/modify-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/es/modify-class.tmpl --- cups-1.3.7/templates/es/modify-class.tmpl.CVE-2010-0540 2006-03-13 13:34:24.000000000 +0000 +++ cups-1.3.7/templates/es/modify-class.tmpl 2010-05-28 12:13:50.917142154 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">Modificar clase {printer_name}</H2> diff -up cups-1.3.7/templates/es/modify-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/es/modify-printer.tmpl --- cups-1.3.7/templates/es/modify-printer.tmpl.CVE-2010-0540 2006-03-13 13:34:24.000000000 +0000 +++ cups-1.3.7/templates/es/modify-printer.tmpl 2010-05-28 12:13:50.918137393 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {?device_uri=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_DEVICE_URI" VALUE="{device_uri}">} {?printer_make_and_model=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_MAKE_AND_MODEL" VALUE="{printer_make_and_model}">} diff -up cups-1.3.7/templates/es/samba-export.tmpl.CVE-2010-0540 cups-1.3.7/templates/es/samba-export.tmpl --- cups-1.3.7/templates/es/samba-export.tmpl.CVE-2010-0540 2007-08-15 20:33:36.000000000 +0100 +++ cups-1.3.7/templates/es/samba-export.tmpl 2010-05-28 12:13:50.919137083 +0100 @@ -10,6 +10,7 @@ function select_printers() { --></SCRIPT> <FORM METHOD="POST" ACTION="/admin/" NAME="export_samba"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="export-samba"> <H2 CLASS="title">Exportar impresoras a Samba</H2> diff -up cups-1.3.7/templates/es/set-printer-options-header.tmpl.CVE-2010-0540 cups-1.3.7/templates/es/set-printer-options-header.tmpl --- cups-1.3.7/templates/es/set-printer-options-header.tmpl.CVE-2010-0540 2006-03-13 13:34:24.000000000 +0000 +++ cups-1.3.7/templates/es/set-printer-options-header.tmpl 2010-05-28 12:13:50.920012534 +0100 @@ -1,3 +1,4 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> diff -up cups-1.3.7/templates/es/users.tmpl.CVE-2010-0540 cups-1.3.7/templates/es/users.tmpl --- cups-1.3.7/templates/es/users.tmpl.CVE-2010-0540 2006-03-13 13:34:24.000000000 +0000 +++ cups-1.3.7/templates/es/users.tmpl 2010-05-28 12:13:50.920012534 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{OP}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> {IS_CLASS?<INPUT TYPE="HIDDEN" NAME="IS_CLASS" VALUE="{IS_CLASS}">:} diff -up cups-1.3.7/templates/et/add-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/et/add-class.tmpl --- cups-1.3.7/templates/et/add-class.tmpl.CVE-2010-0540 2006-10-02 17:02:23.000000000 +0100 +++ cups-1.3.7/templates/et/add-class.tmpl 2010-05-28 12:13:50.921013101 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">Klassi lisamine</H2> diff -up cups-1.3.7/templates/et/add-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/et/add-printer.tmpl --- cups-1.3.7/templates/et/add-printer.tmpl.CVE-2010-0540 2007-02-10 19:37:59.000000000 +0000 +++ cups-1.3.7/templates/et/add-printer.tmpl 2010-05-28 12:13:50.921013101 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {device_uri?<INPUT TYPE="HIDDEN" NAME="DEVICE_URI" VALUE="{device_uri}">:} diff -up cups-1.3.7/templates/et/admin.tmpl.CVE-2010-0540 cups-1.3.7/templates/et/admin.tmpl --- cups-1.3.7/templates/et/admin.tmpl.CVE-2010-0540 2007-03-19 16:01:28.000000000 +0000 +++ cups-1.3.7/templates/et/admin.tmpl 2010-05-28 12:13:50.922012094 +0100 @@ -59,6 +59,7 @@ CLASS="button"></A> <BLOCKQUOTE>{SETTINGS_ERROR}</BLOCKQUOTE>: <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <P><B>Serveri põhiseadistused:</B></P> diff -up cups-1.3.7/templates/et/choose-device.tmpl.CVE-2010-0540 cups-1.3.7/templates/et/choose-device.tmpl --- cups-1.3.7/templates/et/choose-device.tmpl.CVE-2010-0540 2006-10-02 17:02:23.000000000 +0100 +++ cups-1.3.7/templates/et/choose-device.tmpl 2010-05-28 12:13:50.922012094 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/et/choose-make.tmpl.CVE-2010-0540 cups-1.3.7/templates/et/choose-make.tmpl --- cups-1.3.7/templates/et/choose-make.tmpl.CVE-2010-0540 2006-10-02 17:02:23.000000000 +0100 +++ cups-1.3.7/templates/et/choose-make.tmpl 2010-05-28 12:13:50.923012685 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/et/choose-model.tmpl.CVE-2010-0540 cups-1.3.7/templates/et/choose-model.tmpl --- cups-1.3.7/templates/et/choose-model.tmpl.CVE-2010-0540 2006-10-02 17:02:23.000000000 +0100 +++ cups-1.3.7/templates/et/choose-model.tmpl 2010-05-28 12:13:50.924012055 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/et/choose-serial.tmpl.CVE-2010-0540 cups-1.3.7/templates/et/choose-serial.tmpl --- cups-1.3.7/templates/et/choose-serial.tmpl.CVE-2010-0540 2006-10-02 17:02:23.000000000 +0100 +++ cups-1.3.7/templates/et/choose-serial.tmpl 2010-05-28 12:13:50.924012055 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/et/choose-uri.tmpl.CVE-2010-0540 cups-1.3.7/templates/et/choose-uri.tmpl --- cups-1.3.7/templates/et/choose-uri.tmpl.CVE-2010-0540 2006-10-02 17:02:23.000000000 +0100 +++ cups-1.3.7/templates/et/choose-uri.tmpl 2010-05-28 12:13:50.925013795 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/et/edit-config.tmpl.CVE-2010-0540 cups-1.3.7/templates/et/edit-config.tmpl --- cups-1.3.7/templates/et/edit-config.tmpl.CVE-2010-0540 2007-07-25 00:47:12.000000000 +0100 +++ cups-1.3.7/templates/et/edit-config.tmpl 2010-05-28 12:13:50.925013795 +0100 @@ -8,7 +8,7 @@ function reset_config() <H2 CLASS="title">Serveri seadistustefail</H2> <FORM NAME="cups" METHOD="POST" ACTION="/admin/"> - +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="config-server"> <TEXTAREA NAME="CUPSDCONF" COLS="80" ROWS="25">{CUPSDCONF}</TEXTAREA> diff -up cups-1.3.7/templates/et/modify-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/et/modify-class.tmpl --- cups-1.3.7/templates/et/modify-class.tmpl.CVE-2010-0540 2006-10-02 17:02:23.000000000 +0100 +++ cups-1.3.7/templates/et/modify-class.tmpl 2010-05-28 12:13:50.927012438 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">Klassi {printer_name} muutmine</H2> diff -up cups-1.3.7/templates/et/modify-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/et/modify-printer.tmpl --- cups-1.3.7/templates/et/modify-printer.tmpl.CVE-2010-0540 2006-10-02 17:02:23.000000000 +0100 +++ cups-1.3.7/templates/et/modify-printer.tmpl 2010-05-28 12:13:50.934011906 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {?device_uri=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_DEVICE_URI" VALUE="{device_uri}">} {?printer_make_and_model=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_MAKE_AND_MODEL" VALUE="{printer_make_and_model}">} diff -up cups-1.3.7/templates/et/samba-export.tmpl.CVE-2010-0540 cups-1.3.7/templates/et/samba-export.tmpl --- cups-1.3.7/templates/et/samba-export.tmpl.CVE-2010-0540 2006-10-02 17:02:23.000000000 +0100 +++ cups-1.3.7/templates/et/samba-export.tmpl 2010-05-28 12:13:50.935012096 +0100 @@ -10,6 +10,7 @@ function select_printers() { --></SCRIPT> <FORM METHOD="POST" ACTION="/admin/" NAME="export_samba"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="export-samba"> <H2 CLASS="title">Printerite eksport Sambasse</H2> diff -up cups-1.3.7/templates/et/set-printer-options-header.tmpl.CVE-2010-0540 cups-1.3.7/templates/et/set-printer-options-header.tmpl --- cups-1.3.7/templates/et/set-printer-options-header.tmpl.CVE-2010-0540 2006-10-02 17:02:23.000000000 +0100 +++ cups-1.3.7/templates/et/set-printer-options-header.tmpl 2010-05-28 12:13:50.935012096 +0100 @@ -1,3 +1,4 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> diff -up cups-1.3.7/templates/et/users.tmpl.CVE-2010-0540 cups-1.3.7/templates/et/users.tmpl --- cups-1.3.7/templates/et/users.tmpl.CVE-2010-0540 2006-10-02 17:02:23.000000000 +0100 +++ cups-1.3.7/templates/et/users.tmpl 2010-05-28 12:13:50.936012207 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{OP}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> {IS_CLASS?<INPUT TYPE="HIDDEN" NAME="IS_CLASS" VALUE="{IS_CLASS}">:} diff -up cups-1.3.7/templates/fr/add-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/fr/add-class.tmpl --- cups-1.3.7/templates/fr/add-class.tmpl.CVE-2010-0540 2007-02-05 19:37:04.000000000 +0000 +++ cups-1.3.7/templates/fr/add-class.tmpl 2010-05-28 12:13:50.937013261 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">Ajouter une classe</H2> diff -up cups-1.3.7/templates/fr/add-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/fr/add-printer.tmpl --- cups-1.3.7/templates/fr/add-printer.tmpl.CVE-2010-0540 2007-02-10 19:37:59.000000000 +0000 +++ cups-1.3.7/templates/fr/add-printer.tmpl 2010-05-28 12:13:50.937013261 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {device_uri?<INPUT TYPE="HIDDEN" NAME="DEVICE_URI" VALUE="{device_uri}">:} diff -up cups-1.3.7/templates/fr/admin.tmpl.CVE-2010-0540 cups-1.3.7/templates/fr/admin.tmpl --- cups-1.3.7/templates/fr/admin.tmpl.CVE-2010-0540 2007-03-19 16:01:28.000000000 +0000 +++ cups-1.3.7/templates/fr/admin.tmpl 2010-05-28 12:13:50.938012219 +0100 @@ -59,6 +59,7 @@ CLASS="button"></A> <BLOCKQUOTE>{SETTINGS_ERROR}</BLOCKQUOTE>: <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <P><B>Paramètres de base du serveur :</B></P> diff -up cups-1.3.7/templates/fr/choose-device.tmpl.CVE-2010-0540 cups-1.3.7/templates/fr/choose-device.tmpl --- cups-1.3.7/templates/fr/choose-device.tmpl.CVE-2010-0540 2007-02-05 19:37:04.000000000 +0000 +++ cups-1.3.7/templates/fr/choose-device.tmpl 2010-05-28 12:13:50.938012219 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/fr/choose-make.tmpl.CVE-2010-0540 cups-1.3.7/templates/fr/choose-make.tmpl --- cups-1.3.7/templates/fr/choose-make.tmpl.CVE-2010-0540 2007-02-05 19:37:04.000000000 +0000 +++ cups-1.3.7/templates/fr/choose-make.tmpl 2010-05-28 12:13:50.939012735 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/fr/choose-model.tmpl.CVE-2010-0540 cups-1.3.7/templates/fr/choose-model.tmpl --- cups-1.3.7/templates/fr/choose-model.tmpl.CVE-2010-0540 2007-02-05 19:37:04.000000000 +0000 +++ cups-1.3.7/templates/fr/choose-model.tmpl 2010-05-28 12:13:50.940012435 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/fr/choose-serial.tmpl.CVE-2010-0540 cups-1.3.7/templates/fr/choose-serial.tmpl --- cups-1.3.7/templates/fr/choose-serial.tmpl.CVE-2010-0540 2007-02-05 19:37:04.000000000 +0000 +++ cups-1.3.7/templates/fr/choose-serial.tmpl 2010-05-28 12:13:50.940012435 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/fr/choose-uri.tmpl.CVE-2010-0540 cups-1.3.7/templates/fr/choose-uri.tmpl --- cups-1.3.7/templates/fr/choose-uri.tmpl.CVE-2010-0540 2007-02-05 19:37:04.000000000 +0000 +++ cups-1.3.7/templates/fr/choose-uri.tmpl 2010-05-28 12:13:50.941011985 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/fr/edit-config.tmpl.CVE-2010-0540 cups-1.3.7/templates/fr/edit-config.tmpl --- cups-1.3.7/templates/fr/edit-config.tmpl.CVE-2010-0540 2007-07-25 00:47:12.000000000 +0100 +++ cups-1.3.7/templates/fr/edit-config.tmpl 2010-05-28 12:13:50.941011985 +0100 @@ -8,7 +8,7 @@ function reset_config() <H2 CLASS="title">Ficher de configuration du serveur</H2> <FORM NAME="cups" METHOD="POST" ACTION="/admin/"> - +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="config-server"> <TEXTAREA NAME="CUPSDCONF" COLS="80" ROWS="25">{CUPSDCONF}</TEXTAREA> diff -up cups-1.3.7/templates/fr/job-move.tmpl.CVE-2010-0540 cups-1.3.7/templates/fr/job-move.tmpl --- cups-1.3.7/templates/fr/job-move.tmpl.CVE-2010-0540 2007-02-05 19:37:04.000000000 +0000 +++ cups-1.3.7/templates/fr/job-move.tmpl 2010-05-28 12:13:50.942012010 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/{SECTION}/{job_id?:{printer_name}}"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {job_id?<INPUT TYPE="HIDDEN" NAME="JOB_ID" VALUE="{job_id}">:} diff -up cups-1.3.7/templates/fr/modify-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/fr/modify-class.tmpl --- cups-1.3.7/templates/fr/modify-class.tmpl.CVE-2010-0540 2007-02-05 19:37:04.000000000 +0000 +++ cups-1.3.7/templates/fr/modify-class.tmpl 2010-05-28 12:13:50.943012196 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">Modifier la classe {printer_name}</H2> diff -up cups-1.3.7/templates/fr/modify-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/fr/modify-printer.tmpl --- cups-1.3.7/templates/fr/modify-printer.tmpl.CVE-2010-0540 2007-02-05 19:37:04.000000000 +0000 +++ cups-1.3.7/templates/fr/modify-printer.tmpl 2010-05-28 12:13:50.943012196 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {?device_uri=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_DEVICE_URI" VALUE="{device_uri}">} {?printer_make_and_model=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_MAKE_AND_MODEL" VALUE="{printer_make_and_model}">} diff -up cups-1.3.7/templates/fr/samba-export.tmpl.CVE-2010-0540 cups-1.3.7/templates/fr/samba-export.tmpl --- cups-1.3.7/templates/fr/samba-export.tmpl.CVE-2010-0540 2007-02-05 19:37:04.000000000 +0000 +++ cups-1.3.7/templates/fr/samba-export.tmpl 2010-05-28 12:13:50.944012167 +0100 @@ -10,6 +10,7 @@ function select_printers() { --></SCRIPT> <FORM METHOD="POST" ACTION="/admin/" NAME="export_samba"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="export-samba"> <H2 CLASS="title">Exporter des imprimantes vers SAMBA</H2> diff -up cups-1.3.7/templates/fr/set-printer-options-header.tmpl.CVE-2010-0540 cups-1.3.7/templates/fr/set-printer-options-header.tmpl --- cups-1.3.7/templates/fr/set-printer-options-header.tmpl.CVE-2010-0540 2007-02-05 19:37:04.000000000 +0000 +++ cups-1.3.7/templates/fr/set-printer-options-header.tmpl 2010-05-28 12:13:50.944012167 +0100 @@ -1,3 +1,4 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> diff -up cups-1.3.7/templates/fr/users.tmpl.CVE-2010-0540 cups-1.3.7/templates/fr/users.tmpl --- cups-1.3.7/templates/fr/users.tmpl.CVE-2010-0540 2007-02-05 19:37:04.000000000 +0000 +++ cups-1.3.7/templates/fr/users.tmpl 2010-05-28 12:13:50.946012053 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{OP}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> {IS_CLASS?<INPUT TYPE="HIDDEN" NAME="IS_CLASS" VALUE="{IS_CLASS}">:} diff -up cups-1.3.7/templates/he/add-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/he/add-class.tmpl --- cups-1.3.7/templates/he/add-class.tmpl.CVE-2010-0540 2007-04-02 15:31:49.000000000 +0100 +++ cups-1.3.7/templates/he/add-class.tmpl 2010-05-28 12:13:50.946012053 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">הוסף מחלקה</H2> diff -up cups-1.3.7/templates/he/add-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/he/add-printer.tmpl --- cups-1.3.7/templates/he/add-printer.tmpl.CVE-2010-0540 2007-04-02 15:31:49.000000000 +0100 +++ cups-1.3.7/templates/he/add-printer.tmpl 2010-05-28 12:13:50.947012319 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">הוסף מדפסת חדשה</H2> diff -up cups-1.3.7/templates/he/admin.tmpl.CVE-2010-0540 cups-1.3.7/templates/he/admin.tmpl --- cups-1.3.7/templates/he/admin.tmpl.CVE-2010-0540 2007-04-02 15:31:49.000000000 +0100 +++ cups-1.3.7/templates/he/admin.tmpl 2010-05-28 12:13:50.947012319 +0100 @@ -59,6 +59,7 @@ CLASS="button"></A> <BLOCKQUOTE>{SETTINGS_ERROR}</BLOCKQUOTE>: <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <P><B>הגדרות שרת בסיסיות:</B></P> diff -up cups-1.3.7/templates/he/choose-device.tmpl.CVE-2010-0540 cups-1.3.7/templates/he/choose-device.tmpl --- cups-1.3.7/templates/he/choose-device.tmpl.CVE-2010-0540 2007-04-02 15:31:49.000000000 +0100 +++ cups-1.3.7/templates/he/choose-device.tmpl 2010-05-28 12:13:50.948012570 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/he/choose-make.tmpl.CVE-2010-0540 cups-1.3.7/templates/he/choose-make.tmpl --- cups-1.3.7/templates/he/choose-make.tmpl.CVE-2010-0540 2007-04-02 15:31:49.000000000 +0100 +++ cups-1.3.7/templates/he/choose-make.tmpl 2010-05-28 12:13:50.949012134 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/he/choose-model.tmpl.CVE-2010-0540 cups-1.3.7/templates/he/choose-model.tmpl --- cups-1.3.7/templates/he/choose-model.tmpl.CVE-2010-0540 2007-04-02 15:31:49.000000000 +0100 +++ cups-1.3.7/templates/he/choose-model.tmpl 2010-05-28 12:13:50.949012134 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/he/choose-serial.tmpl.CVE-2010-0540 cups-1.3.7/templates/he/choose-serial.tmpl --- cups-1.3.7/templates/he/choose-serial.tmpl.CVE-2010-0540 2007-04-02 15:31:49.000000000 +0100 +++ cups-1.3.7/templates/he/choose-serial.tmpl 2010-05-28 12:13:50.950012085 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/he/choose-uri.tmpl.CVE-2010-0540 cups-1.3.7/templates/he/choose-uri.tmpl --- cups-1.3.7/templates/he/choose-uri.tmpl.CVE-2010-0540 2007-04-02 15:31:49.000000000 +0100 +++ cups-1.3.7/templates/he/choose-uri.tmpl 2010-05-28 12:13:50.950012085 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/he/edit-config.tmpl.CVE-2010-0540 cups-1.3.7/templates/he/edit-config.tmpl --- cups-1.3.7/templates/he/edit-config.tmpl.CVE-2010-0540 2007-07-25 00:47:12.000000000 +0100 +++ cups-1.3.7/templates/he/edit-config.tmpl 2010-05-28 12:13:50.951014126 +0100 @@ -8,7 +8,7 @@ function reset_config() <H2 CLASS="title">קובץ הגדרות של השרת</H2> <FORM NAME="cups" METHOD="POST" ACTION="/admin/"> - +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="config-server"> <TEXTAREA NAME="CUPSDCONF" COLS="80" ROWS="25" dir=ltr>{CUPSDCONF}</TEXTAREA> diff -up cups-1.3.7/templates/he/job-move.tmpl.CVE-2010-0540 cups-1.3.7/templates/he/job-move.tmpl --- cups-1.3.7/templates/he/job-move.tmpl.CVE-2010-0540 2007-04-02 15:31:49.000000000 +0100 +++ cups-1.3.7/templates/he/job-move.tmpl 2010-05-28 12:13:50.951014126 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/{SECTION}/{job_id?:{printer_name}}"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {job_id?<INPUT TYPE="HIDDEN" NAME="JOB_ID" VALUE="{job_id}">:} diff -up cups-1.3.7/templates/he/modify-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/he/modify-class.tmpl --- cups-1.3.7/templates/he/modify-class.tmpl.CVE-2010-0540 2007-04-02 15:31:49.000000000 +0100 +++ cups-1.3.7/templates/he/modify-class.tmpl 2010-05-28 12:13:50.952012553 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">שנה מחלקה {printer_name}</H2> diff -up cups-1.3.7/templates/he/modify-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/he/modify-printer.tmpl --- cups-1.3.7/templates/he/modify-printer.tmpl.CVE-2010-0540 2007-04-02 15:31:49.000000000 +0100 +++ cups-1.3.7/templates/he/modify-printer.tmpl 2010-05-28 12:13:50.953012358 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {?device_uri=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_DEVICE_URI" VALUE="{device_uri}">} {?printer_make_and_model=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_MAKE_AND_MODEL" VALUE="{printer_make_and_model}">} diff -up cups-1.3.7/templates/he/samba-export.tmpl.CVE-2010-0540 cups-1.3.7/templates/he/samba-export.tmpl --- cups-1.3.7/templates/he/samba-export.tmpl.CVE-2010-0540 2007-04-02 15:31:49.000000000 +0100 +++ cups-1.3.7/templates/he/samba-export.tmpl 2010-05-28 12:13:50.953012358 +0100 @@ -10,6 +10,7 @@ function select_printers() { --></SCRIPT> <FORM METHOD="POST" ACTION="/admin/" NAME="export_samba"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="export-samba"> <H2 CLASS="title">ייצא מדפסות ל Samba</H2> diff -up cups-1.3.7/templates/he/set-printer-options-header.tmpl.CVE-2010-0540 cups-1.3.7/templates/he/set-printer-options-header.tmpl --- cups-1.3.7/templates/he/set-printer-options-header.tmpl.CVE-2010-0540 2007-04-02 15:31:49.000000000 +0100 +++ cups-1.3.7/templates/he/set-printer-options-header.tmpl 2010-05-28 12:13:50.954012128 +0100 @@ -1,3 +1,4 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> diff -up cups-1.3.7/templates/he/users.tmpl.CVE-2010-0540 cups-1.3.7/templates/he/users.tmpl --- cups-1.3.7/templates/he/users.tmpl.CVE-2010-0540 2007-04-02 15:31:49.000000000 +0100 +++ cups-1.3.7/templates/he/users.tmpl 2010-05-28 12:13:50.955011923 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{OP}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> {IS_CLASS?<INPUT TYPE="HIDDEN" NAME="IS_CLASS" VALUE="{IS_CLASS}">:} diff -up cups-1.3.7/templates/it/add-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/it/add-class.tmpl --- cups-1.3.7/templates/it/add-class.tmpl.CVE-2010-0540 2006-11-16 13:33:33.000000000 +0000 +++ cups-1.3.7/templates/it/add-class.tmpl 2010-05-28 12:13:50.955011923 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">Aggiungi classe</H2> diff -up cups-1.3.7/templates/it/add-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/it/add-printer.tmpl --- cups-1.3.7/templates/it/add-printer.tmpl.CVE-2010-0540 2007-02-10 19:37:59.000000000 +0000 +++ cups-1.3.7/templates/it/add-printer.tmpl 2010-05-28 12:13:50.956012094 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {device_uri?<INPUT TYPE="HIDDEN" NAME="DEVICE_URI" VALUE="{device_uri}">:} diff -up cups-1.3.7/templates/it/admin.tmpl.CVE-2010-0540 cups-1.3.7/templates/it/admin.tmpl --- cups-1.3.7/templates/it/admin.tmpl.CVE-2010-0540 2007-03-19 16:01:28.000000000 +0000 +++ cups-1.3.7/templates/it/admin.tmpl 2010-05-28 12:13:50.957013212 +0100 @@ -59,6 +59,7 @@ CLASS="button"></A> <BLOCKQUOTE>{SETTINGS_ERROR}</BLOCKQUOTE>: <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <P><B>Impostazioni di base del server:</B></P> diff -up cups-1.3.7/templates/it/choose-device.tmpl.CVE-2010-0540 cups-1.3.7/templates/it/choose-device.tmpl --- cups-1.3.7/templates/it/choose-device.tmpl.CVE-2010-0540 2006-11-16 13:33:33.000000000 +0000 +++ cups-1.3.7/templates/it/choose-device.tmpl 2010-05-28 12:13:50.959013750 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/it/choose-make.tmpl.CVE-2010-0540 cups-1.3.7/templates/it/choose-make.tmpl --- cups-1.3.7/templates/it/choose-make.tmpl.CVE-2010-0540 2006-11-16 13:33:33.000000000 +0000 +++ cups-1.3.7/templates/it/choose-make.tmpl 2010-05-28 12:13:50.960013154 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/it/choose-model.tmpl.CVE-2010-0540 cups-1.3.7/templates/it/choose-model.tmpl --- cups-1.3.7/templates/it/choose-model.tmpl.CVE-2010-0540 2006-11-16 13:33:33.000000000 +0000 +++ cups-1.3.7/templates/it/choose-model.tmpl 2010-05-28 12:13:50.962011967 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/it/choose-serial.tmpl.CVE-2010-0540 cups-1.3.7/templates/it/choose-serial.tmpl --- cups-1.3.7/templates/it/choose-serial.tmpl.CVE-2010-0540 2006-11-16 13:33:33.000000000 +0000 +++ cups-1.3.7/templates/it/choose-serial.tmpl 2010-05-28 12:13:50.962011967 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/it/choose-uri.tmpl.CVE-2010-0540 cups-1.3.7/templates/it/choose-uri.tmpl --- cups-1.3.7/templates/it/choose-uri.tmpl.CVE-2010-0540 2006-11-16 13:33:33.000000000 +0000 +++ cups-1.3.7/templates/it/choose-uri.tmpl 2010-05-28 12:13:50.963013973 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/it/edit-config.tmpl.CVE-2010-0540 cups-1.3.7/templates/it/edit-config.tmpl --- cups-1.3.7/templates/it/edit-config.tmpl.CVE-2010-0540 2007-07-25 00:47:12.000000000 +0100 +++ cups-1.3.7/templates/it/edit-config.tmpl 2010-05-28 12:13:50.965012626 +0100 @@ -8,7 +8,7 @@ function reset_config() <H2 CLASS="title">File di configurazione del server</H2> <FORM NAME="cups" METHOD="POST" ACTION="/admin/"> - +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="config-server"> <TEXTAREA NAME="CUPSDCONF" COLS="80" ROWS="25">{CUPSDCONF}</TEXTAREA> diff -up cups-1.3.7/templates/it/job-move.tmpl.CVE-2010-0540 cups-1.3.7/templates/it/job-move.tmpl --- cups-1.3.7/templates/it/job-move.tmpl.CVE-2010-0540 2006-11-16 13:33:33.000000000 +0000 +++ cups-1.3.7/templates/it/job-move.tmpl 2010-05-28 12:13:50.972011878 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/{SECTION}/{job_id?:{printer_name}}"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {job_id?<INPUT TYPE="HIDDEN" NAME="JOB_ID" VALUE="{job_id}">:} diff -up cups-1.3.7/templates/it/modify-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/it/modify-class.tmpl --- cups-1.3.7/templates/it/modify-class.tmpl.CVE-2010-0540 2006-11-16 13:33:33.000000000 +0000 +++ cups-1.3.7/templates/it/modify-class.tmpl 2010-05-28 12:13:50.973012470 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">Modifica classe {printer_name}</H2> diff -up cups-1.3.7/templates/it/modify-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/it/modify-printer.tmpl --- cups-1.3.7/templates/it/modify-printer.tmpl.CVE-2010-0540 2006-11-16 13:33:33.000000000 +0000 +++ cups-1.3.7/templates/it/modify-printer.tmpl 2010-05-28 12:13:50.973012470 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {?device_uri=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_DEVICE_URI" VALUE="{device_uri}">} {?printer_make_and_model=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_MAKE_AND_MODEL" VALUE="{printer_make_and_model}">} diff -up cups-1.3.7/templates/it/samba-export.tmpl.CVE-2010-0540 cups-1.3.7/templates/it/samba-export.tmpl --- cups-1.3.7/templates/it/samba-export.tmpl.CVE-2010-0540 2006-11-16 13:33:33.000000000 +0000 +++ cups-1.3.7/templates/it/samba-export.tmpl 2010-05-28 12:13:50.974011979 +0100 @@ -10,6 +10,7 @@ function select_printers() { --></SCRIPT> <FORM METHOD="POST" ACTION="/admin/" NAME="export_samba"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="export-samba"> <H2 CLASS="title">Esporta stampanti su Samba</H2> diff -up cups-1.3.7/templates/it/set-printer-options-header.tmpl.CVE-2010-0540 cups-1.3.7/templates/it/set-printer-options-header.tmpl --- cups-1.3.7/templates/it/set-printer-options-header.tmpl.CVE-2010-0540 2006-11-16 13:33:33.000000000 +0000 +++ cups-1.3.7/templates/it/set-printer-options-header.tmpl 2010-05-28 12:13:50.975012085 +0100 @@ -1,3 +1,4 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> diff -up cups-1.3.7/templates/it/users.tmpl.CVE-2010-0540 cups-1.3.7/templates/it/users.tmpl --- cups-1.3.7/templates/it/users.tmpl.CVE-2010-0540 2006-11-16 13:33:33.000000000 +0000 +++ cups-1.3.7/templates/it/users.tmpl 2010-05-28 12:13:50.975012085 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{OP}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> {IS_CLASS?<INPUT TYPE="HIDDEN" NAME="IS_CLASS" VALUE="{IS_CLASS}">:} diff -up cups-1.3.7/templates/ja/add-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/ja/add-class.tmpl --- cups-1.3.7/templates/ja/add-class.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/ja/add-class.tmpl 2010-05-28 12:13:50.976012286 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">クラスの追加</H2> diff -up cups-1.3.7/templates/ja/add-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/ja/add-printer.tmpl --- cups-1.3.7/templates/ja/add-printer.tmpl.CVE-2010-0540 2007-02-10 19:37:59.000000000 +0000 +++ cups-1.3.7/templates/ja/add-printer.tmpl 2010-05-28 12:13:50.976012286 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {device_uri?<INPUT TYPE="HIDDEN" NAME="DEVICE_URI" VALUE="{device_uri}">:} diff -up cups-1.3.7/templates/ja/add-rss-subscription.tmpl.CVE-2010-0540 cups-1.3.7/templates/ja/add-rss-subscription.tmpl --- cups-1.3.7/templates/ja/add-rss-subscription.tmpl.CVE-2010-0540 2007-10-10 23:56:24.000000000 +0100 +++ cups-1.3.7/templates/ja/add-rss-subscription.tmpl 2010-05-28 12:13:50.977012588 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="add-rss-subscription"> <H2 CLASS="title">RSS 購読を追加</H2> diff -up cups-1.3.7/templates/ja/admin.tmpl.CVE-2010-0540 cups-1.3.7/templates/ja/admin.tmpl --- cups-1.3.7/templates/ja/admin.tmpl.CVE-2010-0540 2007-10-10 23:56:24.000000000 +0100 +++ cups-1.3.7/templates/ja/admin.tmpl 2010-05-28 12:13:50.978012152 +0100 @@ -53,6 +53,7 @@ CLASS="button"></A> <BLOCKQUOTE>{SETTINGS_ERROR}</BLOCKQUOTE>: <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <P><B>基本サーバ設定:</B></P> diff -up cups-1.3.7/templates/ja/choose-device.tmpl.CVE-2010-0540 cups-1.3.7/templates/ja/choose-device.tmpl --- cups-1.3.7/templates/ja/choose-device.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/ja/choose-device.tmpl 2010-05-28 12:13:50.978012152 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/ja/choose-make.tmpl.CVE-2010-0540 cups-1.3.7/templates/ja/choose-make.tmpl --- cups-1.3.7/templates/ja/choose-make.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/ja/choose-make.tmpl 2010-05-28 12:13:50.979012153 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/ja/choose-model.tmpl.CVE-2010-0540 cups-1.3.7/templates/ja/choose-model.tmpl --- cups-1.3.7/templates/ja/choose-model.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/ja/choose-model.tmpl 2010-05-28 12:13:50.979012153 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/ja/choose-serial.tmpl.CVE-2010-0540 cups-1.3.7/templates/ja/choose-serial.tmpl --- cups-1.3.7/templates/ja/choose-serial.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/ja/choose-serial.tmpl 2010-05-28 12:13:50.980011727 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/ja/choose-uri.tmpl.CVE-2010-0540 cups-1.3.7/templates/ja/choose-uri.tmpl --- cups-1.3.7/templates/ja/choose-uri.tmpl.CVE-2010-0540 2006-03-18 12:56:48.000000000 +0000 +++ cups-1.3.7/templates/ja/choose-uri.tmpl 2010-05-28 12:13:50.981012831 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/ja/edit-config.tmpl.CVE-2010-0540 cups-1.3.7/templates/ja/edit-config.tmpl --- cups-1.3.7/templates/ja/edit-config.tmpl.CVE-2010-0540 2007-07-25 00:47:12.000000000 +0100 +++ cups-1.3.7/templates/ja/edit-config.tmpl 2010-05-28 12:13:50.982012375 +0100 @@ -8,7 +8,7 @@ function reset_config() <H2 CLASS="title">サーバ設定ファイル</H2> <FORM NAME="cups" METHOD="POST" ACTION="/admin/"> - +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="config-server"> <TEXTAREA NAME="CUPSDCONF" COLS="80" ROWS="25">{CUPSDCONF}</TEXTAREA> diff -up cups-1.3.7/templates/ja/job-move.tmpl.CVE-2010-0540 cups-1.3.7/templates/ja/job-move.tmpl --- cups-1.3.7/templates/ja/job-move.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/ja/job-move.tmpl 2010-05-28 12:13:50.982012375 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/{SECTION}/{job_id?:{printer_name}}"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {job_id?<INPUT TYPE="HIDDEN" NAME="JOB_ID" VALUE="{job_id}">:} diff -up cups-1.3.7/templates/ja/modify-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/ja/modify-class.tmpl --- cups-1.3.7/templates/ja/modify-class.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/ja/modify-class.tmpl 2010-05-28 12:13:50.983012165 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">クラス {printer_name} の変更</H2> diff -up cups-1.3.7/templates/ja/modify-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/ja/modify-printer.tmpl --- cups-1.3.7/templates/ja/modify-printer.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/ja/modify-printer.tmpl 2010-05-28 12:13:50.984012392 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {?device_uri=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_DEVICE_URI" VALUE="{device_uri}">} {?printer_make_and_model=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_MAKE_AND_MODEL" VALUE="{printer_make_and_model}">} diff -up cups-1.3.7/templates/ja/samba-export.tmpl.CVE-2010-0540 cups-1.3.7/templates/ja/samba-export.tmpl --- cups-1.3.7/templates/ja/samba-export.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/ja/samba-export.tmpl 2010-05-28 12:13:51.003012192 +0100 @@ -10,6 +10,7 @@ function select_printers() { --></SCRIPT> <FORM METHOD="POST" ACTION="/admin/" NAME="export_samba"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="export-samba"> <H2 CLASS="title">プリンタを Samba にエキスポート</H2> diff -up cups-1.3.7/templates/ja/users.tmpl.CVE-2010-0540 cups-1.3.7/templates/ja/users.tmpl --- cups-1.3.7/templates/ja/users.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/ja/users.tmpl 2010-05-28 12:13:51.004012473 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{OP}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> {IS_CLASS?<INPUT TYPE="HIDDEN" NAME="IS_CLASS" VALUE="{IS_CLASS}">:} diff -up cups-1.3.7/templates/job-move.tmpl.CVE-2010-0540 cups-1.3.7/templates/job-move.tmpl --- cups-1.3.7/templates/job-move.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/job-move.tmpl 2010-05-28 12:13:51.004012473 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/{SECTION}/{job_id?:{printer_name}}"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {job_id?<INPUT TYPE="HIDDEN" NAME="JOB_ID" VALUE="{job_id}">:} diff -up cups-1.3.7/templates/modify-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/modify-class.tmpl --- cups-1.3.7/templates/modify-class.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/modify-class.tmpl 2010-05-28 12:13:51.005012384 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">Modify Class {printer_name}</H2> diff -up cups-1.3.7/templates/modify-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/modify-printer.tmpl --- cups-1.3.7/templates/modify-printer.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/modify-printer.tmpl 2010-05-28 12:13:51.005012384 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {?device_uri=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_DEVICE_URI" VALUE="{device_uri}">} {?printer_make_and_model=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_MAKE_AND_MODEL" VALUE="{printer_make_and_model}">} diff -up cups-1.3.7/templates/pl/add-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/pl/add-class.tmpl --- cups-1.3.7/templates/pl/add-class.tmpl.CVE-2010-0540 2006-05-15 20:05:22.000000000 +0100 +++ cups-1.3.7/templates/pl/add-class.tmpl 2010-05-28 12:13:51.006011958 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">Dodaj klasę</H2> diff -up cups-1.3.7/templates/pl/add-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/pl/add-printer.tmpl --- cups-1.3.7/templates/pl/add-printer.tmpl.CVE-2010-0540 2007-02-10 19:37:59.000000000 +0000 +++ cups-1.3.7/templates/pl/add-printer.tmpl 2010-05-28 12:13:51.006011958 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {device_uri?<INPUT TYPE="HIDDEN" NAME="DEVICE_URI" VALUE="{device_uri}">:} diff -up cups-1.3.7/templates/pl/admin.tmpl.CVE-2010-0540 cups-1.3.7/templates/pl/admin.tmpl --- cups-1.3.7/templates/pl/admin.tmpl.CVE-2010-0540 2007-03-19 16:01:28.000000000 +0000 +++ cups-1.3.7/templates/pl/admin.tmpl 2010-05-28 12:13:51.007012209 +0100 @@ -57,6 +57,7 @@ CLASS="button"></A> <BLOCKQUOTE>{SETTINGS_ERROR}</BLOCKQUOTE>: <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <P><B>Podstawowe ustawienia serwera:</B></P> diff -up cups-1.3.7/templates/pl/choose-device.tmpl.CVE-2010-0540 cups-1.3.7/templates/pl/choose-device.tmpl --- cups-1.3.7/templates/pl/choose-device.tmpl.CVE-2010-0540 2006-05-15 20:05:22.000000000 +0100 +++ cups-1.3.7/templates/pl/choose-device.tmpl 2010-05-28 12:13:51.008012350 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/pl/choose-make.tmpl.CVE-2010-0540 cups-1.3.7/templates/pl/choose-make.tmpl --- cups-1.3.7/templates/pl/choose-make.tmpl.CVE-2010-0540 2006-05-15 20:05:22.000000000 +0100 +++ cups-1.3.7/templates/pl/choose-make.tmpl 2010-05-28 12:13:51.008012350 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/pl/choose-model.tmpl.CVE-2010-0540 cups-1.3.7/templates/pl/choose-model.tmpl --- cups-1.3.7/templates/pl/choose-model.tmpl.CVE-2010-0540 2006-05-15 20:05:22.000000000 +0100 +++ cups-1.3.7/templates/pl/choose-model.tmpl 2010-05-28 12:13:51.009011970 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/pl/choose-serial.tmpl.CVE-2010-0540 cups-1.3.7/templates/pl/choose-serial.tmpl --- cups-1.3.7/templates/pl/choose-serial.tmpl.CVE-2010-0540 2006-05-15 20:05:22.000000000 +0100 +++ cups-1.3.7/templates/pl/choose-serial.tmpl 2010-05-28 12:13:51.010012477 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/pl/choose-uri.tmpl.CVE-2010-0540 cups-1.3.7/templates/pl/choose-uri.tmpl --- cups-1.3.7/templates/pl/choose-uri.tmpl.CVE-2010-0540 2006-05-15 20:05:22.000000000 +0100 +++ cups-1.3.7/templates/pl/choose-uri.tmpl 2010-05-28 12:13:51.010012477 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/pl/edit-config.tmpl.CVE-2010-0540 cups-1.3.7/templates/pl/edit-config.tmpl --- cups-1.3.7/templates/pl/edit-config.tmpl.CVE-2010-0540 2007-07-25 00:47:12.000000000 +0100 +++ cups-1.3.7/templates/pl/edit-config.tmpl 2010-05-28 12:13:51.011011986 +0100 @@ -8,7 +8,7 @@ function reset_config() <H2 CLASS="title">Plik Konfiguracji Serwera</H2> <FORM NAME="cups" METHOD="POST" ACTION="/admin/"> - +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="config-server"> <TEXTAREA NAME="CUPSDCONF" COLS="80" ROWS="25">{CUPSDCONF}</TEXTAREA> diff -up cups-1.3.7/templates/pl/job-move.tmpl.CVE-2010-0540 cups-1.3.7/templates/pl/job-move.tmpl --- cups-1.3.7/templates/pl/job-move.tmpl.CVE-2010-0540 2006-05-15 20:05:22.000000000 +0100 +++ cups-1.3.7/templates/pl/job-move.tmpl 2010-05-28 12:13:51.011011986 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/{SECTION}/{job_id?:{printer_name}}"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {job_id?<INPUT TYPE="HIDDEN" NAME="JOB_ID" VALUE="{job_id}">:} diff -up cups-1.3.7/templates/pl/modify-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/pl/modify-class.tmpl --- cups-1.3.7/templates/pl/modify-class.tmpl.CVE-2010-0540 2006-05-15 20:05:22.000000000 +0100 +++ cups-1.3.7/templates/pl/modify-class.tmpl 2010-05-28 12:13:51.012012569 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">Zmodyfikuj klasę {printer_name}</H2> diff -up cups-1.3.7/templates/pl/modify-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/pl/modify-printer.tmpl --- cups-1.3.7/templates/pl/modify-printer.tmpl.CVE-2010-0540 2006-05-15 20:05:22.000000000 +0100 +++ cups-1.3.7/templates/pl/modify-printer.tmpl 2010-05-28 12:13:51.013011887 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {?device_uri=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_DEVICE_URI" VALUE="{device_uri}">} {?printer_make_and_model=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_MAKE_AND_MODEL" VALUE="{printer_make_and_model}">} diff -up cups-1.3.7/templates/pl/samba-export.tmpl.CVE-2010-0540 cups-1.3.7/templates/pl/samba-export.tmpl --- cups-1.3.7/templates/pl/samba-export.tmpl.CVE-2010-0540 2006-05-15 20:05:22.000000000 +0100 +++ cups-1.3.7/templates/pl/samba-export.tmpl 2010-05-28 12:13:51.014012268 +0100 @@ -10,6 +10,7 @@ function select_printers() { --></SCRIPT> <FORM METHOD="POST" ACTION="/admin/" NAME="export_samba"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="export-samba"> <H2 CLASS="title">Wyeksportuj drukarki do Samby</H2> diff -up cups-1.3.7/templates/pl/set-printer-options-header.tmpl.CVE-2010-0540 cups-1.3.7/templates/pl/set-printer-options-header.tmpl --- cups-1.3.7/templates/pl/set-printer-options-header.tmpl.CVE-2010-0540 2006-04-22 05:05:45.000000000 +0100 +++ cups-1.3.7/templates/pl/set-printer-options-header.tmpl 2010-05-28 12:13:51.021012087 +0100 @@ -1,3 +1,4 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> diff -up cups-1.3.7/templates/pl/users.tmpl.CVE-2010-0540 cups-1.3.7/templates/pl/users.tmpl --- cups-1.3.7/templates/pl/users.tmpl.CVE-2010-0540 2006-05-15 20:05:22.000000000 +0100 +++ cups-1.3.7/templates/pl/users.tmpl 2010-05-28 12:13:51.023013833 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{OP}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> {IS_CLASS?<INPUT TYPE="HIDDEN" NAME="IS_CLASS" VALUE="{IS_CLASS}">:} diff -up cups-1.3.7/templates/samba-export.tmpl.CVE-2010-0540 cups-1.3.7/templates/samba-export.tmpl --- cups-1.3.7/templates/samba-export.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/samba-export.tmpl 2010-05-28 12:13:51.024012856 +0100 @@ -10,6 +10,7 @@ function select_printers() { --></SCRIPT> <FORM METHOD="POST" ACTION="/admin/" NAME="export_samba"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="export-samba"> <H2 CLASS="title">Export Printers to Samba</H2> diff -up cups-1.3.7/templates/set-printer-options-header.tmpl.CVE-2010-0540 cups-1.3.7/templates/set-printer-options-header.tmpl --- cups-1.3.7/templates/set-printer-options-header.tmpl.CVE-2010-0540 2005-12-15 22:03:40.000000000 +0000 +++ cups-1.3.7/templates/set-printer-options-header.tmpl 2010-05-28 12:13:51.024012856 +0100 @@ -1,3 +1,4 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> diff -up cups-1.3.7/templates/sv/add-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/sv/add-class.tmpl --- cups-1.3.7/templates/sv/add-class.tmpl.CVE-2010-0540 2006-04-17 15:50:45.000000000 +0100 +++ cups-1.3.7/templates/sv/add-class.tmpl 2010-05-28 12:13:51.025012225 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">Lägg till klass</H2> diff -up cups-1.3.7/templates/sv/add-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/sv/add-printer.tmpl --- cups-1.3.7/templates/sv/add-printer.tmpl.CVE-2010-0540 2007-02-10 19:37:59.000000000 +0000 +++ cups-1.3.7/templates/sv/add-printer.tmpl 2010-05-28 12:13:51.025012225 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {device_uri?<INPUT TYPE="HIDDEN" NAME="DEVICE_URI" VALUE="{device_uri}">:} diff -up cups-1.3.7/templates/sv/admin.tmpl.CVE-2010-0540 cups-1.3.7/templates/sv/admin.tmpl --- cups-1.3.7/templates/sv/admin.tmpl.CVE-2010-0540 2007-03-19 16:01:28.000000000 +0000 +++ cups-1.3.7/templates/sv/admin.tmpl 2010-05-28 12:13:51.026015208 +0100 @@ -59,6 +59,7 @@ CLASS="button"></A> <BLOCKQUOTE>{SETTINGS_ERROR}</BLOCKQUOTE>: <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <P><B>Grundläggande serverinställningar:</B></P> diff -up cups-1.3.7/templates/sv/choose-device.tmpl.CVE-2010-0540 cups-1.3.7/templates/sv/choose-device.tmpl --- cups-1.3.7/templates/sv/choose-device.tmpl.CVE-2010-0540 2006-04-17 15:50:45.000000000 +0100 +++ cups-1.3.7/templates/sv/choose-device.tmpl 2010-05-28 12:13:51.027012166 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/sv/choose-make.tmpl.CVE-2010-0540 cups-1.3.7/templates/sv/choose-make.tmpl --- cups-1.3.7/templates/sv/choose-make.tmpl.CVE-2010-0540 2006-04-17 15:50:45.000000000 +0100 +++ cups-1.3.7/templates/sv/choose-make.tmpl 2010-05-28 12:13:51.027012166 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/sv/choose-model.tmpl.CVE-2010-0540 cups-1.3.7/templates/sv/choose-model.tmpl --- cups-1.3.7/templates/sv/choose-model.tmpl.CVE-2010-0540 2006-04-17 15:50:45.000000000 +0100 +++ cups-1.3.7/templates/sv/choose-model.tmpl 2010-05-28 12:13:51.028012126 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/sv/choose-serial.tmpl.CVE-2010-0540 cups-1.3.7/templates/sv/choose-serial.tmpl --- cups-1.3.7/templates/sv/choose-serial.tmpl.CVE-2010-0540 2006-04-17 15:50:45.000000000 +0100 +++ cups-1.3.7/templates/sv/choose-serial.tmpl 2010-05-28 12:13:51.028012126 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/sv/choose-uri.tmpl.CVE-2010-0540 cups-1.3.7/templates/sv/choose-uri.tmpl --- cups-1.3.7/templates/sv/choose-uri.tmpl.CVE-2010-0540 2006-04-17 15:50:45.000000000 +0100 +++ cups-1.3.7/templates/sv/choose-uri.tmpl 2010-05-28 12:13:51.029011956 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/sv/edit-config.tmpl.CVE-2010-0540 cups-1.3.7/templates/sv/edit-config.tmpl --- cups-1.3.7/templates/sv/edit-config.tmpl.CVE-2010-0540 2007-07-25 00:47:12.000000000 +0100 +++ cups-1.3.7/templates/sv/edit-config.tmpl 2010-05-28 12:13:51.029011956 +0100 @@ -8,7 +8,7 @@ function reset_config() <H2 CLASS="title">Serverkonfigurationsfil</H2> <FORM NAME="cups" METHOD="POST" ACTION="/admin/"> - +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="config-server"> <TEXTAREA NAME="CUPSDCONF" COLS="80" ROWS="25">{CUPSDCONF}</TEXTAREA> diff -up cups-1.3.7/templates/sv/job-move.tmpl.CVE-2010-0540 cups-1.3.7/templates/sv/job-move.tmpl --- cups-1.3.7/templates/sv/job-move.tmpl.CVE-2010-0540 2006-04-17 15:50:45.000000000 +0100 +++ cups-1.3.7/templates/sv/job-move.tmpl 2010-05-28 12:13:51.030012158 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/{SECTION}/{job_id?:{printer_name}}"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {job_id?<INPUT TYPE="HIDDEN" NAME="JOB_ID" VALUE="{job_id}">:} diff -up cups-1.3.7/templates/sv/modify-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/sv/modify-class.tmpl --- cups-1.3.7/templates/sv/modify-class.tmpl.CVE-2010-0540 2006-04-17 15:50:45.000000000 +0100 +++ cups-1.3.7/templates/sv/modify-class.tmpl 2010-05-28 12:13:51.031011878 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">Modifiera klass {printer_name}</H2> diff -up cups-1.3.7/templates/sv/modify-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/sv/modify-printer.tmpl --- cups-1.3.7/templates/sv/modify-printer.tmpl.CVE-2010-0540 2006-04-17 15:50:45.000000000 +0100 +++ cups-1.3.7/templates/sv/modify-printer.tmpl 2010-05-28 12:13:51.031011878 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {?device_uri=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_DEVICE_URI" VALUE="{device_uri}">} {?printer_make_and_model=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_MAKE_AND_MODEL" VALUE="{printer_make_and_model}">} diff -up cups-1.3.7/templates/sv/samba-export.tmpl.CVE-2010-0540 cups-1.3.7/templates/sv/samba-export.tmpl --- cups-1.3.7/templates/sv/samba-export.tmpl.CVE-2010-0540 2006-04-17 15:50:45.000000000 +0100 +++ cups-1.3.7/templates/sv/samba-export.tmpl 2010-05-28 12:13:51.032011934 +0100 @@ -10,6 +10,7 @@ function select_printers() { --></SCRIPT> <FORM METHOD="POST" ACTION="/admin/" NAME="export_samba"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="export-samba"> <H2 CLASS="title">Exportera skrivare till Samba</H2> diff -up cups-1.3.7/templates/sv/set-printer-options-header.tmpl.CVE-2010-0540 cups-1.3.7/templates/sv/set-printer-options-header.tmpl --- cups-1.3.7/templates/sv/set-printer-options-header.tmpl.CVE-2010-0540 2006-04-17 15:50:45.000000000 +0100 +++ cups-1.3.7/templates/sv/set-printer-options-header.tmpl 2010-05-28 12:13:51.033012350 +0100 @@ -1,3 +1,4 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> diff -up cups-1.3.7/templates/sv/users.tmpl.CVE-2010-0540 cups-1.3.7/templates/sv/users.tmpl --- cups-1.3.7/templates/sv/users.tmpl.CVE-2010-0540 2006-04-17 15:50:45.000000000 +0100 +++ cups-1.3.7/templates/sv/users.tmpl 2010-05-28 12:13:51.034013133 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{OP}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> {IS_CLASS?<INPUT TYPE="HIDDEN" NAME="IS_CLASS" VALUE="{IS_CLASS}">:} diff -up cups-1.3.7/templates/users.tmpl.CVE-2010-0540 cups-1.3.7/templates/users.tmpl --- cups-1.3.7/templates/users.tmpl.CVE-2010-0540 2006-03-04 02:00:43.000000000 +0000 +++ cups-1.3.7/templates/users.tmpl 2010-05-28 12:13:51.034013133 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{OP}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> {IS_CLASS?<INPUT TYPE="HIDDEN" NAME="IS_CLASS" VALUE="{IS_CLASS}">:} diff -up cups-1.3.7/templates/zh_TW/add-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/zh_TW/add-class.tmpl --- cups-1.3.7/templates/zh_TW/add-class.tmpl.CVE-2010-0540 2007-05-08 20:48:20.000000000 +0100 +++ cups-1.3.7/templates/zh_TW/add-class.tmpl 2010-05-28 12:13:51.035012061 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">加入分類</H2> diff -up cups-1.3.7/templates/zh_TW/add-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/zh_TW/add-printer.tmpl --- cups-1.3.7/templates/zh_TW/add-printer.tmpl.CVE-2010-0540 2007-05-08 20:48:20.000000000 +0100 +++ cups-1.3.7/templates/zh_TW/add-printer.tmpl 2010-05-28 12:13:51.035012061 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">加入新的印表機</H2> diff -up cups-1.3.7/templates/zh_TW/admin.tmpl.CVE-2010-0540 cups-1.3.7/templates/zh_TW/admin.tmpl --- cups-1.3.7/templates/zh_TW/admin.tmpl.CVE-2010-0540 2007-05-08 20:48:20.000000000 +0100 +++ cups-1.3.7/templates/zh_TW/admin.tmpl 2010-05-28 12:13:51.036011931 +0100 @@ -59,6 +59,7 @@ CLASS="button"></A> <BLOCKQUOTE>{SETTINGS_ERROR}</BLOCKQUOTE>: <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <P><B>基本伺服器設定值:</B></P> diff -up cups-1.3.7/templates/zh_TW/choose-device.tmpl.CVE-2010-0540 cups-1.3.7/templates/zh_TW/choose-device.tmpl --- cups-1.3.7/templates/zh_TW/choose-device.tmpl.CVE-2010-0540 2007-05-08 20:48:20.000000000 +0100 +++ cups-1.3.7/templates/zh_TW/choose-device.tmpl 2010-05-28 12:13:51.037011941 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/zh_TW/choose-make.tmpl.CVE-2010-0540 cups-1.3.7/templates/zh_TW/choose-make.tmpl --- cups-1.3.7/templates/zh_TW/choose-make.tmpl.CVE-2010-0540 2007-05-08 20:48:20.000000000 +0100 +++ cups-1.3.7/templates/zh_TW/choose-make.tmpl 2010-05-28 12:13:51.037011941 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/zh_TW/choose-model.tmpl.CVE-2010-0540 cups-1.3.7/templates/zh_TW/choose-model.tmpl --- cups-1.3.7/templates/zh_TW/choose-model.tmpl.CVE-2010-0540 2007-05-08 20:48:20.000000000 +0100 +++ cups-1.3.7/templates/zh_TW/choose-model.tmpl 2010-05-28 12:13:51.038012498 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin" ENCTYPE="multipart/form-data"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/zh_TW/choose-serial.tmpl.CVE-2010-0540 cups-1.3.7/templates/zh_TW/choose-serial.tmpl --- cups-1.3.7/templates/zh_TW/choose-serial.tmpl.CVE-2010-0540 2007-05-08 20:48:20.000000000 +0100 +++ cups-1.3.7/templates/zh_TW/choose-serial.tmpl 2010-05-28 12:13:51.038012498 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/zh_TW/choose-uri.tmpl.CVE-2010-0540 cups-1.3.7/templates/zh_TW/choose-uri.tmpl --- cups-1.3.7/templates/zh_TW/choose-uri.tmpl.CVE-2010-0540 2007-05-08 20:48:20.000000000 +0100 +++ cups-1.3.7/templates/zh_TW/choose-uri.tmpl 2010-05-28 12:13:51.039012243 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_LOCATION" VALUE="{?printer_location}"> diff -up cups-1.3.7/templates/zh_TW/edit-config.tmpl.CVE-2010-0540 cups-1.3.7/templates/zh_TW/edit-config.tmpl --- cups-1.3.7/templates/zh_TW/edit-config.tmpl.CVE-2010-0540 2007-07-25 00:47:12.000000000 +0100 +++ cups-1.3.7/templates/zh_TW/edit-config.tmpl 2010-05-28 12:13:51.040012013 +0100 @@ -8,7 +8,7 @@ function reset_config() <H2 CLASS="title">伺服器配置檔案</H2> <FORM NAME="cups" METHOD="POST" ACTION="/admin/"> - +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="config-server"> <TEXTAREA NAME="CUPSDCONF" COLS="80" ROWS="25">{CUPSDCONF}</TEXTAREA> diff -up cups-1.3.7/templates/zh_TW/job-move.tmpl.CVE-2010-0540 cups-1.3.7/templates/zh_TW/job-move.tmpl --- cups-1.3.7/templates/zh_TW/job-move.tmpl.CVE-2010-0540 2007-05-08 20:48:20.000000000 +0100 +++ cups-1.3.7/templates/zh_TW/job-move.tmpl 2010-05-28 12:13:51.040012013 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/{SECTION}/{job_id?:{printer_name}}"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {job_id?<INPUT TYPE="HIDDEN" NAME="JOB_ID" VALUE="{job_id}">:} diff -up cups-1.3.7/templates/zh_TW/modify-class.tmpl.CVE-2010-0540 cups-1.3.7/templates/zh_TW/modify-class.tmpl --- cups-1.3.7/templates/zh_TW/modify-class.tmpl.CVE-2010-0540 2007-05-08 20:48:20.000000000 +0100 +++ cups-1.3.7/templates/zh_TW/modify-class.tmpl 2010-05-28 12:13:51.041011989 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> <H2 CLASS="title">修改分類 {printer_name}</H2> diff -up cups-1.3.7/templates/zh_TW/modify-printer.tmpl.CVE-2010-0540 cups-1.3.7/templates/zh_TW/modify-printer.tmpl --- cups-1.3.7/templates/zh_TW/modify-printer.tmpl.CVE-2010-0540 2007-05-08 20:48:20.000000000 +0100 +++ cups-1.3.7/templates/zh_TW/modify-printer.tmpl 2010-05-28 12:13:51.042012301 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> {?device_uri=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_DEVICE_URI" VALUE="{device_uri}">} {?printer_make_and_model=?:<INPUT TYPE="HIDDEN" NAME="CURRENT_MAKE_AND_MODEL" VALUE="{printer_make_and_model}">} diff -up cups-1.3.7/templates/zh_TW/samba-export.tmpl.CVE-2010-0540 cups-1.3.7/templates/zh_TW/samba-export.tmpl --- cups-1.3.7/templates/zh_TW/samba-export.tmpl.CVE-2010-0540 2007-05-08 20:48:20.000000000 +0100 +++ cups-1.3.7/templates/zh_TW/samba-export.tmpl 2010-05-28 12:13:51.043012185 +0100 @@ -10,6 +10,7 @@ function select_printers() { --></SCRIPT> <FORM METHOD="POST" ACTION="/admin/" NAME="export_samba"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="export-samba"> <H2 CLASS="title">匯出印表機至 Samba</H2> diff -up cups-1.3.7/templates/zh_TW/set-printer-options-header.tmpl.CVE-2010-0540 cups-1.3.7/templates/zh_TW/set-printer-options-header.tmpl --- cups-1.3.7/templates/zh_TW/set-printer-options-header.tmpl.CVE-2010-0540 2007-05-08 20:48:20.000000000 +0100 +++ cups-1.3.7/templates/zh_TW/set-printer-options-header.tmpl 2010-05-28 12:13:51.043012185 +0100 @@ -1,3 +1,4 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{op}"> diff -up cups-1.3.7/templates/zh_TW/users.tmpl.CVE-2010-0540 cups-1.3.7/templates/zh_TW/users.tmpl --- cups-1.3.7/templates/zh_TW/users.tmpl.CVE-2010-0540 2007-05-08 20:48:20.000000000 +0100 +++ cups-1.3.7/templates/zh_TW/users.tmpl 2010-05-28 12:13:51.045012513 +0100 @@ -1,4 +1,5 @@ <FORM METHOD="POST" ACTION="/admin"> +<INPUT TYPE="HIDDEN" NAME="org.cups.sid" VALUE="{$org.cups.sid}"> <INPUT TYPE="HIDDEN" NAME="OP" VALUE="{OP}"> <INPUT TYPE="HIDDEN" NAME="PRINTER_NAME" VALUE="{printer_name}"> {IS_CLASS?<INPUT TYPE="HIDDEN" NAME="IS_CLASS" VALUE="{IS_CLASS}">:}