Releases of Drupal contributions that are compatible with version 5.x of Drupal Core
Prevent users with 'administer workflow' permission from using workflow and state names containing XSS.
This release of External Links fixes several bugs discovered after the 1.7 release.
DRUPAL-SA-CONTRIB-2009-076
The previous release of the module suffered from a Cross Site Scripting (XSS) vulnerability. Such an attack may lead to a malicious user gaining full admin access. The release fixes these issues.
For more details on the security release: http://drupal.org/node/611078
Changes since DRUPAL-5--1-5:
Security update.
SA-CONTRIB-2009-079 - vCard - Cross Site Scripting