forward 6.x-1.20

Security update
Insecure

Check to ensure that the page being forwarded refers to an internal path. This prevents someone from hard coding a forward link to an unscrupulous external site.

forward 7.x-1.1

Security update
Insecure

Adds check to ensure that the page being forwarded refers to an internal path. This prevents someone from hard coding a forward link to an unscrupulous external site.

addresses 6.x-1.11

Security update
New features
Bug fixes

- The security issue fixes an XSS vulnerability in the Addresses main module. (SA-CONTRIB-2011-036 - Addresses - Cross Site Scripting)

- Issue #1216746: Addresses province field does not maintain attributes after ajax call. by dkinzer: Addresses province field does not maintain attributes after ajax call.
- Fixed a comment and indentation.
- Issue #906976: Country set to 'us' (United States) when no value supplied in non-required address by derhasi and usonian and dwightaspinwall: Country set to 'us' (United States) when no value supplied in non-required address.
- Issue #1161654: PHP notice fixes by mikl: PHP notice fixes.
- Issue #378498: Migration from Address Field for CCK: Migration from Address Field for CCK 5.x to Addresses 6.x.
- Issue #1111940: Incorrect user access and #1111974: Loading wrong user when editing by sean3z: mishandle of permissions to edit user addresses by user administrators.
- Issue #1075762: Wrong city name by Patrizio: fix Napoli city name.
- Removing translation directories. (automatic)
- Stripping CVS keywords. (automatic)
- Better language support as per #812772: Translation doesn't work on the "state / province" item with ajax (if country field is displayed)
- Applied a fix for top-countries in CCK fields #822076: Patch to allow designation of "top countries"
- Patch to allow CCK tokens from the Addresses fields #463668: Address fields or field does not show up in Replacement Patterns (Tokens)
- Attempt to add a Weight to the addresses fields #958662: Placement of Addresses fieldset in user forms
- Added another flag so we can choose to show the user form: (1) on the registration form, or not; (2) on the edit form, or not.
- Added support for Feeds #975684: Support for Feeds module
- Added Armed Forces "states".
- Fix the CCK reference to 'field'.'field' into 'filter'.'field'. #324331: CCK addresses fields not displayed in views

sparql 7.x-2.0-alpha2

Security update
New features
Bug fixes

- #1234584 by linclark: Fixed notices in sparql_registry_load_by_uri().
- #1210582 by linclark: Changed Add support for URL parameters.
- #1222066 by cwells73 | linclark: Changed SPARQL package's directory structure.
- #1209598 by cwells73: Fixed access control on sparql endpoint.
- #1214510 by linclark: Changed 'endpoint' property to 'uri' on endpoint objects.
- #1213192 by linclark: Changed SPARQL Registry field integration unnecessary.
- #847142 by linclark | JeremyFrench, stuarttaylor: Added error reporting to _sparql_request().
- #1212996 by scor: remove old code which was used to pass Drupal's prefixes to ARC2 SPARQL endpoint
Issue #1211898 by linclark: Changed API to take endpoint object instead of $endpoint + $options.
#1176844 by linclark: Changed Move sparql_endpoint_initialize() to main sparql module.
#1119490 by Remon: SPARQL endpoints registry redirects outside the admin area upon save
#1148258 by Remon: SPARQL Registry should validate that Endpoint is full URL
Issue #1177938 by cwells73: Clean up sparql.info.
Issue #1195840 by Remon: sparql_endpoint_initialize should take ['host'] into account
Issue #1178042 by scor: Fixed Align SPARQL endpoint module with the new rdfx API for build the RDF model.
Issue #1175628 by cwells73 | linclark: Remove crufty sparql.inc file.

take_control 6.x-2.2

Security update
Bug fixes

1) Security fix that can lead to CSRF attacks. Upgrading to the latest version is strongly advised. See SA-CONTRIB-2012-075 - Take Control - Cross Site Request Forgery (CSRF) for more details.
2) #834464 by vincent: Fixed call-time pass-by-reference deprecated warning. Also, switched to 6.x-2.x branch for committing changes instead of the HEAD branch.
3) Support for Drupal installations not having clean urls enabled.
4) Code clean-up.
5) A couple of other minor fixes.

autocomplete_deluxe 7.x-1.0-beta5

Security update
Bug fixes
Insecure

#1103466: Fixed bug with autocomplete_path setting.
Fixed info file.

Pages

Subscribe with RSS Subscribe to RSS - Security update