aberdeen 6.x-1.11

Security update

Fixes SA-CONTRIB-2012-081 - Aberdeen - Cross Site Scripting

If you copied code from the aberdeen_breadcrumb function into a custom sub-theme's template.php file you should compare your code to the changes to ensure that menu_get_active_title() is properly wrapped in check plain like:

check_plain(menu_get_active_title());

ad 6.x-2.3

Security update

See SA-CONTRIB-2012-77 - Advertisement - Cross Site Scripting & Information Disclosure.

  • bug #797274 by tacituseu: apply modified version of tacituseu's patch to get charts to appear
  • bug #1252536 by osopolar: fix iframe scrolling options
  • Clean up AHAH selection of type
  • Require a debug key to show debugging information

Pages

Subscribe with RSS Subscribe to RSS - Security update