Download comment_upload-4.7.x-0.1.tar.gztar.gz 10.78 KB
MD5: e28f76a25df1822d54f94ce88ee12b03
SHA-1: 91e9fef67deb76a6e72bfa34c9efd2190e1570bd
SHA-256: 2009ed38b879700ac3e46cd51c37ab0940699147e44f7ab322aa50fbe53c9f83
Download comment_upload-4.7.x-0.1.zipzip 11.99 KB
MD5: 380cf4b74ee83dc7c2200abf76ad8dec
SHA-1: 948f72132174a3457d7de4674addaf66906fba37
SHA-256: eb7ead873937351c474f18331a10f7908c6ffaf681adaa27714b528078cd00f9

Release info

Created by: Heine
Created on: January 30, 2008 - 20:56
Last updated: January 31, 2008 - 00:49
Core compatibility: 4.7.x
Release type: Security update

Release notes

The release fixes an arbitrary file upload issue. See SA-2008-015 for details.

Changes since DRUPAL-4-7:

  • #72235 - fixed incompatability with private download method by creating a hook_file_download and designated comment u
    pload tables.
  • fix table prefixes in .install
  • #88495 - make sure files and table entries are deleted when the parent node is removed.
  • Improved README.txt
  • #111931 - don't save to sequences, when there are no comment uploads to be upgraded
  • #110962 - Support PostgreSQL, make sure MySQL definition matches.
  • #113585 - fix sql error in create table statement
  • #113258 - Backported support for multiple inline images
  • #126312 - records were removed but actual files were not deleted, due to a missing file_delete.
  • #216024 (SA-2008-015) - cast $comment to an object before passing it to validation routines.