SA-CONTRIB-2010-064 - Ubercart MIGS Payment Gateway - Web Parameter Tampering was released today. A few D5 uc_migs3rdparty users have requested that a D5 backport be supplied. I can't support uc_migs3rdparty but I'm happy to get a 5.x-dev release out which people can transfer to.

If you're feeling keen -

* Please test uc_migs-DRUPAL-5
* You can help by adding an .install file which copies or converts the variables from the uc_migs3rdparty prefix to uc_migs

CommentFileSizeAuthor
#2 uc_migs3rdparty.tar_.gz4.79 KBlarowlan
#2 uc_migs.patch2.7 KBlarowlan
Support from Acquia helps fund testing for Drupal Acquia logo

Comments

xurizaemon’s picture

Status: Active » Needs work

It's been reported to me that the version in CVS for D5 is actually code for Drupal 6 (see hook_menu() etc). I must have incorrectly checked in that code to the 5.x branch back in September. At least there's no danger of this code mistakenly getting used again :)

Any contributions welcome.

larowlan’s picture

FileSize
2.7 KB
4.79 KB

New module is attached, this was derived from beta-1, if you've got a different version, use the patch instead

xurizaemon’s picture

Status: Needs work » Needs review

Thanks. Committed a version of uc_migs-DRUPAL-5 which hopefully is a drop-in replacement for uc_migs3rdparty and includes the fix (retains uc_migs3rdparty prefixes on variables so should be no changes required).

xurizaemon’s picture

Title: Backport of fix for SA-CONTRIB-2010-064 » SA-CONTRIB-2010-064 backport for Drupal 5.x
xurizaemon’s picture

Status: Needs review » Fixed

gave the 5.x-1.x-dev release a spin and a shakedown during halftime

checked in some fixes - grab the next dev build from the module page, should be good

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.