take_control 6.x-2.2

Security update
Bug fixes

1) Security fix that can lead to CSRF attacks. Upgrading to the latest version is strongly advised. See SA-CONTRIB-2012-075 - Take Control - Cross Site Request Forgery (CSRF) for more details.
2) #834464 by vincent: Fixed call-time pass-by-reference deprecated warning. Also, switched to 6.x-2.x branch for committing changes instead of the HEAD branch.
3) Support for Drupal installations not having clean urls enabled.
4) Code clean-up.
5) A couple of other minor fixes.

autocomplete_deluxe 7.x-1.0-beta5

Security update
Bug fixes
Insecure

#1103466: Fixed bug with autocomplete_path setting.
Fixed info file.

ds 7.x-1.3

Security update
New features
Bug fixes
Insecure

Changes since 7.x-1.2:

mail_logger 5.x-1.1

Security update

The module did not previously sanitize the from, to, subject, or body output from a saved email against cross-site scripting attacks.

mail_logger 6.x-1.1

Security update
Bug fixes

The module did not previously sanitize the from, to, subject, or body output from a saved email against cross-site scripting attacks.
Better support for PHP 5.3
SA-CONTRIB-2011-032
#389990: Incorrect use of hook_boot()

Pages

Subscribe with RSS Subscribe to RSS - Security update