8 Commits

Author SHA1 Message Date
stephan
6b41a25273 update drupal core to 6.19, addresses SA-CORE-2010-002:
- OpenID authentication bypass
 - File download access bypass
 - Comment unpublishing bypass
 - Actions cross site scripting

gory details at http://drupal.org/node/880476
no database upgrade required for this update.
2010-09-14 10:14:33 +00:00
espie
234aae7770 minor updates. 2010-06-03 16:25:23 +00:00
stephan
f691a20cad security update to 6.16, fixes DRUPAL-SA-CORE-2010-001.
ok jasper@, "I can vouch for it" @espie
2010-03-05 09:09:23 +00:00
espie
68d5c7474a DRUPAL-SA-CORE-2009-009
Vulnerabilities in Contact module, XSS if malicious users can create menus.
2009-12-18 19:05:57 +00:00
espie
bf080de18c security update (DRUPAL-SA-CORE-2009-008):
if you use OpenID, or your uploads are badly configured, you have a
security risk.
2009-09-20 11:56:37 +00:00
espie
1834e327c5 update to current versions 2009-07-15 10:33:38 +00:00
sthen
868bef47bd update to 6.12, fixes an xss issue. ok espie@ 2009-05-15 21:21:27 +00:00
espie
7738104118 hate cvs... "core" directory with stuff in it should be okay by default.
noticed by naddy@
2009-04-03 23:26:48 +00:00