bueditor has a feature to exec php. We should block it.

Comments

greggles’s picture

Status: Active » Needs review
StatusFileSize
new382 bytes

See #2006502: does 7.x-1.x version allow admins to execute php? to determine if we need this for 7.x.

greggles’s picture

For 7.x we need "administer bueditor"

greggles’s picture

Version: 6.x-1.x-dev » 7.x-1.x-dev
Status: Needs review » Fixed
StatusFileSize
new1.36 KB

Killes reviewed in irc.

6.x-1.x committed/pushed http://drupalcode.org/project/paranoia.git/commit/362999e

7.x-1.x attached committed and pushed http://drupalcode.org/project/paranoia.git/commit/fbdf15c

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.

killes@www.drop.org’s picture

and deployed