SA-CONTRIB-2014-026 - Mime Mail - Access bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2014-026
  • Project: Mime Mail (third-party module)
  • Version: 6.x, 7.x
  • Date: 2014-February-26
  • Security risk: Not critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass

Video Embedding

After three years embedding youtube videos I now have a problem...viewing the same from my website. www.carbuyersformula.com I'm at a loss, browser OK, latest Adobe, but cannot view video posted just last week? Any ideas I need to address? Glen

SA-CONTRIB-2014-024 - Content Lock - CSRF

SA-CONTRIB-2014-023 - Project Issue File Review - XSS

  • Advisory ID: DRUPAL-SA-CONTRIB-2014-023
  • Project: Project Issue File Review (third-party module)
  • Version: 6.x
  • Date: 2014-February-26
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

Curl/http_request do not load

Hey Im trying to GET from url

I am using curl and than echo the file and it works, when I call it from my module or it doesn't show, I tried http_request as well and I get the same problem, any ideas?

works

$url = "http://www.site.com/api/users?id=" .$user->name . "&account=user&password=pasword";
      $response = drupal_http_request($url);
	  dpm( $response);
	  }

works

Cannot display "mission statement" in a new theme

Hi folks, read some content here but still do not know how to fix.

My blog type page is based on "elements" theme. This theme contains only 2 areas: leftsidebar and footer.

In admin/build/themes/settings (global settings) I enabled "mission statement". But changing to
admin/build/themes/settings/elements_theme (my theme settings) there is no "mission statement" box to enable.

After stored a "mission statement" in admin/settings/site-information I could not see the content in my elements theme but changing to another theme like garland it shows me the content.

Pages

Subscribe with RSS Subscribe to RSS - Drupal 6.x