Home

New Tech Heroes

New Media and Social Publishing

Navigation

  • Home
  • About
    • Site rules
    • Privacy policy
    • Contact
    • About Tom Kephart
Home

Thought provoking

  • OpenOffice.org 3.0 Releases Monday--Or Get It Early
  • OpenOffice.org 3.0 Releases Monday--Or Get It Early
  • NetVibes Coming to Facebook
  • NetVibes Coming to Facebook
  • Clean Your Workspace—and Keep it That Way
more

Tag cloud

Acquia Adobe AIR amateurs Apple blog blogger blogging blogs browsers buyout CMS content management development Drupal Facebook Firefox flashback friendfeed funny Gmail Google history Internet Internet Explorer jobs Joomla marketing media Microsoft new media offline online Open Source patch Plone privacy reputation Safari Scoble security SEO SharePoint SilverStripe social social media social networking social publishing spam TechCrunch television Tom Kephart upgrade video virtual conversation vulnerability web Web 2.0 WordPress Yahoo

JavaScript

JavaScript vulnerability in Drupal prompts 6.1 release

Submitted by Tom Kephart on Wed, 02/27/2008 - 6:43pm.
  • Drupal
  • JavaScript
  • patch
  • upgrade
  • vulnerability

A "moderately critical" ECMAScript/JavaScript vulnerability in Drupal has been fixed in the latest release, version 6.1. All users of the 6.0 version of Drupal are encouraged to patch their current installations or install the complete version 6.1 files.

A potential cross-site scripting (XSS) vulnerability (SA-2008-018) existed in the handling of titles on content edit forms. A JavaScript function used to escape text wasn't working correctly, and is fixed in the latest version.

The legacy 5.x line of Drupal remains at version 5.7, and is not affected by this vulnerability.

Drupal 6.1 is available for download from the main Drupal website.

Bookmark/Search this post with:
  • Delicious
  • Digg
  • StumbleUpon
  • Reddit
  • Magnoliacom
  • Newsvine
  • Google
  • Technorati
  • Icerocket
  • Add a comment

New Tech Heroes

Editor: Tom Kephart

Grab the RSS feed
or subscribe by email

Add to Technorati Favorites

View Tom Kephart's profile on LinkedIn

Popular content

Today's:

  • [flashback] The Spot - lonelygirl15's beach party ancestors
  • Albert Maruggi: "Jump in the pool"
  • Acquia's Carbon: commercially supported Drupal

All time:

  • JavaScript vulnerability in Drupal prompts 6.1 release
  • Drupal issues maintenance upgrade to 5.7
  • Scoble cries; blogosphere freaks; Jesus returns

Blogroll

Creative Commons License

This work is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.

© 2008 Kephart & Associates, Marine City, Michigan. Our privacy policy.
Powered by Drupal. Customized theme based on Tapestry by RoopleTheme.
Web hosting by pair Networks.

Kephart & Associates