Home

New Tech Heroes

New Media and Social Publishing

Navigation

  • Home
  • About
    • Site rules
    • Privacy policy
    • Contact
    • About Tom Kephart
Home

Thought provoking

  • Joomla! 1.5.4 Released
  • Ira Glass on Getting Creative Work Done
  • Get Productive with Social Media (and Stay Sane)
  • What Social Media Does Best
  • Could Your Google Search Indict You?
  • The end of SEO?
  • It's All Too Much
  • 20+ Must-Have WordPress 2.5 Compatible Plugins
more

Tag cloud

Adobe AIR amateurs Apple blog blogger blogging blogs browsers buyout CMS content management development Drupal Facebook Firefox flashback friendfeed funny Gmail Google history Internet Internet Explorer jobs Joomla Mahalo marketing Microsoft new media online Open Source patch Plone privacy radio reputation Safari Scoble security SEO SharePoint SilverStripe social social networking social publishing spam TechCrunch Tom Kephart upgrade venture capital video virtual conversation Vista vulnerability web Web 2.0 web design WordPress Yahoo

JavaScript vulnerability in Drupal prompts 6.1 release

Submitted by Tom Kephart on Wed, 02/27/2008 - 6:43pm.
  • Drupal
  • JavaScript
  • patch
  • upgrade
  • vulnerability

A "moderately critical" ECMAScript/JavaScript vulnerability in Drupal has been fixed in the latest release, version 6.1. All users of the 6.0 version of Drupal are encouraged to patch their current installations or install the complete version 6.1 files.

A potential cross-site scripting (XSS) vulnerability (SA-2008-018) existed in the handling of titles on content edit forms. A JavaScript function used to escape text wasn't working correctly, and is fixed in the latest version.

The legacy 5.x line of Drupal remains at version 5.7, and is not affected by this vulnerability.

Drupal 6.1 is available for download from the main Drupal website.

Bookmark/Search this post with:
  • Delicious
  • Digg
  • StumbleUpon
  • Reddit
  • Magnoliacom
  • Newsvine
  • Google
  • Technorati
  • Icerocket

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Looks like it is time for an

Submitted by Cheap Punk Clothes (not verified) on Fri, 07/04/2008 - 6:30am.

Looks like it is time for an upgrade then! Thanks.

  • reply

Wow Drupal 6.1 came quickly

Submitted by DUI Attorneys California (not verified) on Tue, 07/01/2008 - 7:48am.

I can't believe that they made a large upgrade to Drupal already, Is 6.2 out yet or know? Thanks for the info, I have to update to fix this problem.

  • reply

Glad I found this. I guess

Submitted by Frankie (not verified) on Sun, 06/29/2008 - 8:19pm.

Glad I found this. I guess it is time for me to upgrade a few sites and close off that vulnerability.

  • reply

برامج نت

Submitted by Anonymous (not verified) on Sat, 06/21/2008 - 2:08pm.

برامج نت

  • reply

Post new comment

The content of this field is kept private and will not be shown publicly.
Input format
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <b> <address> <blockquote> <br> <caption> <center> <code> <dd> <del> <div> <dl> <dt> <em> <font> <h2> <h3> <h4> <h5> <h6> <hr> <i> <img> <li> <ol> <p> <pre> <span> <strong> <sub> <sup> <table> <tbody> <td> <tfoot> <th> <thead> <tr> <u> <ul> <tr>
  • Lines and paragraphs break automatically.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

New Tech Heroes

Editor: Tom Kephart

Grab the RSS feed
or subscribe by email

Add to Technorati Favorites

View Tom Kephart's profile on LinkedIn

Lijit Search


follow TomKephart at http://twitter.com

Popular content

Today's:

  • [flashback] The Spot - lonelygirl15's beach party ancestors
  • Drupal 6.2 release fixes bugs and security issues
  • Wednesday's featured links - March 12, 2008

All time:

  • Drupal issues maintenance upgrade to 5.7
  • Scoble cries; blogosphere freaks; Jesus returns
  • Google Sites: Stone Cold Killa? Perhaps not.

Blogroll

CMS versions

  • Drupal 6.2
    (legacy 5.7)
  • Joomla! 1.5.4
    (legacy 1.0.15)
  • WordPress 2.5.1
    (legacy 2.0.11)
  • Movable Type 4.12
  • Plone 3.1.2
  • CMS Made Simple 1.3.1
  • MODx 0.9.6.1
  • SilverStripe 2.2.2
  • ExpressionEngine 1.6.4
  • Alfresco Community 2.9B
  • Midgard CMS 1.8.8

Creative Commons License

This work is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.

© 2008 Kephart & Associates, Marine City, Michigan. Our privacy policy.
Powered by Drupal. Customized theme based on Tapestry by RoopleTheme.
Web hosting by pair Networks.

Kephart & Associates