Permalink
Browse files

Drupal 6.1; including #227608 (SA-2008-18)

  • Loading branch information...
1 parent 021f59b commit d2e3d172c1c67e6ab22fcb323ed1ad786d4976e0 goba committed Feb 27, 2008
Showing with 14 additions and 12 deletions.
  1. +5 −4 CHANGELOG.txt
  2. +2 −2 includes/common.inc
  3. +3 −2 misc/drupal.js
  4. +2 −2 modules/node/node.pages.inc
  5. +2 −2 modules/system/system.module
View
@@ -1,8 +1,9 @@
-// $Id: CHANGELOG.txt,v 1.253.2.4 2008-02-13 15:39:26 goba Exp $
-
-Drupal 6.1-dev, xxxx-xx-xx (development version)
------------------------
+// $Id: CHANGELOG.txt,v 1.253.2.5 2008-02-27 19:44:44 goba Exp $
+Drupal 6.1, 2008-02-27
+----------------------
+- fixed a variety of small bugs.
+- fixed a security issue (Cross site scripting), see SA-2008-018
Drupal 6.0, 2008-02-13
----------------------
View
@@ -1,5 +1,5 @@
<?php
-// $Id: common.inc,v 1.756.2.6 2008-02-27 11:52:08 goba Exp $
+// $Id: common.inc,v 1.756.2.7 2008-02-27 19:44:44 goba Exp $
/**
* @file
@@ -577,7 +577,7 @@ function drupal_error_handler($errno, $message, $filename, $line, $context) {
return;
}
- if ($errno & (E_ALL)) {
+ if ($errno & (E_ALL ^ E_NOTICE)) {
$types = array(1 => 'error', 2 => 'warning', 4 => 'parse error', 8 => 'notice', 16 => 'core error', 32 => 'core warning', 64 => 'compile error', 128 => 'compile warning', 256 => 'user error', 512 => 'user warning', 1024 => 'user notice', 2048 => 'strict warning', 4096 => 'recoverable fatal error');
// For database errors, we want the line number/file name of the place that
View
@@ -1,4 +1,4 @@
-// $Id: drupal.js,v 1.41.2.1 2008-02-06 12:18:04 goba Exp $
+// $Id: drupal.js,v 1.41.2.2 2008-02-27 19:44:44 goba Exp $
var Drupal = Drupal || { 'settings': {}, 'behaviors': {}, 'themes': {}, 'locale': {} };
@@ -51,7 +51,8 @@ Drupal.checkPlain = function(str) {
str = String(str);
var replace = { '&': '&amp;', '"': '&quot;', '<': '&lt;', '>': '&gt;' };
for (var character in replace) {
- str = str.replace(character, replace[character]);
+ var regex = new RegExp(character, 'g');
+ str = str.replace(regex, replace[character]);
}
return str;
};
@@ -1,5 +1,5 @@
<?php
-// $Id: node.pages.inc,v 1.28 2008-02-03 19:26:10 goba Exp $
+// $Id: node.pages.inc,v 1.28.2.1 2008-02-27 19:44:44 goba Exp $
/**
* @file
@@ -11,7 +11,7 @@
* Menu callback; presents the node editing form, or redirects to delete confirmation.
*/
function node_page_edit($node) {
- drupal_set_title($node->title);
+ drupal_set_title(check_plain($node->title));
return drupal_get_form($node->type .'_node_form', $node);
}
@@ -1,5 +1,5 @@
<?php
-// $Id: system.module,v 1.585.2.7 2008-02-13 15:39:27 goba Exp $
+// $Id: system.module,v 1.585.2.8 2008-02-27 19:44:44 goba Exp $
/**
* @file
@@ -9,7 +9,7 @@
/**
* The current system version.
*/
-define('VERSION', '6.1-dev');
+define('VERSION', '6.1');
/**
* Core API compatibility.

0 comments on commit d2e3d17

Please sign in to comment.