5.x

Releases of Drupal contributions that are compatible with version 5.x of Drupal Core

abuse 5.x-2.1

BTMash - October 21, 2009 - 17:15
Download Size md5 hash
abuse-5.x-2.1.tar.gz 23.94 KB c4ec37e9d6de2fb02a0d8522dc61d4fa
Official release from CVS tag: DRUPAL-5--2-1
Last updated: October 21, 2009 - 17:20

The previous release of the module suffered from a Cross Site Scripting (XSS) vulnerability. Such an attack may lead to a malicious user gaining full admin access. The release fixes these issues.

For more details on the security release: http://drupal.org/node/611078

vcard 5.x-1.4

sanduhrs - October 21, 2009 - 10:03
Download Size md5 hash
vcard-5.x-1.4.tar.gz 10.71 KB 1332dbc0229463ff2d2e6fadfe3c8a2e
Official release from CVS tag: DRUPAL-5--1-4
Last updated: October 21, 2009 - 10:06

Security update.

SA-CONTRIB-2009-079 - vCard - Cross Site Scripting

og_vocab 5.x-1.1

Amitaibu - October 15, 2009 - 07:51
Download Size md5 hash
og_vocab-5.x-1.1.tar.gz 11.02 KB e434454719f96b1e6a8926158a0aa3d1
Official release from CVS tag: DRUPAL-5--1-1
Last updated: October 15, 2009 - 07:55

- Sanitize node title before setting it as the page title.

See SA-CONTRIB-2009-075 - OG Vocabulary 5.x.

webform 5.x-2.8

quicksketch - October 15, 2009 - 01:37
Download Size md5 hash
webform-5.x-2.8.tar.gz 212.98 KB a3730be80ec05d3ea82f5737e1e697bc
Official release from CVS tag: DRUPAL-5--2-8
Last updated: October 15, 2009 - 01:41

This version of Webform addresses two security issues found since the 2.7 release.

- Anonymous user data may be shown to other anonymous users when the page cache is enabled.
- Unsafe markup was allowed in textfield components' prefix and suffix values.

print 5.x-4.9

jcnventura - October 14, 2009 - 22:59
Download Size md5 hash
print-5.x-4.9.tar.gz 161.59 KB b0214dbac239ca76c51a3aac16237d0a
Official release from CVS tag: DRUPAL-5--4-9
Last updated: October 14, 2009 - 23:01

Changes since DRUPAL-5--4-8:

  • SA-CONTRIB-2009-073: remove XSS vulnerability in PF URLs list and unathorized access to node titles
  • Fix #554940: escape mysql query string
  • Fix #566138: add setting to close the window when both the new window and send to printer are enabled
  • Fix #572848 by aether: Use theme_username() for print_mail_form defaults
  • Fix #582104: look for PDF libraries in sites/all/libraries
  • Fix #582360: don't complain about missing e-mail addresses when there's a blank line at the end
  • Fix #578990: enable tokens in the wkhtmltopdf options string
  • Fix #552882: register dompdf's autoload function to prevent fatal errors
  • Fix #597922: remove warning for missing argument in print_mail_form()
  • Fix #599840: use the real page path and not the current URL when determining link visibility
  • Fix #602286: check text string management permissions using Drupal 5 syntax
  • Fix #521776: support wkhtmltopdf in Windows

customfilter 5.x-1.5

kiamlaluno - October 12, 2009 - 15:53
Download Size md5 hash
customfilter-5.x-1.5.tar.gz 16.75 KB e97e756d759d9c3a04dc8ec1a797d1e8
Official release from CVS tag: DRUPAL-5--1-5
Last updated: October 12, 2009 - 15:55

Changes since DRUPAL-5--1-4:

  • #427080 by mr.j, KiamLaLuno: Cache filters per page load for massive performance boost.
  • By KiamLaLuno: Corrected the code that was trying to translate empty strings.
  • By KiamLaLuno: Changed the code to make it more code standards compliant.
Syndicate content
 
 

Drupal is a registered trademark of Dries Buytaert.