This is an update to address an XSS vulnerability. See SA-CONTRIB-2012-140 - Inf08 - Cross Site Scripting (XSS)
Fixed an XSS vulnerability and an error in displaying the form for entering the company name. See SA-CONTRIB-2012-144 Fonecta verify - Cross Site Scripting (XSS) for details.
Fixed an XSS vulnerability and a problem with displaying the form for entering the association registration key. See SA-CONTRIB-2012-143 PRH Search - Cross Site Scripting (XSS) for details.
- Change way to execute the convert command - Change permissions
SA-CONTRIB-2012-139 - PDFThumb OS Injection
SA-CONTRIB-2012-138 - Exposed Filter Data - Cross Site Scripting (XSS)
Added a token check to the heartbeat_comments so no vulnerability can be exploited.
SA-CONTRIB-2012-137 - Heartbeat - Cross Site Request Forgery (CSRF) in heartbeat_comments