Geeklog 1.3.9sr2 and 1.3.8-1sr6
- Friday, October 08 2004 @ 02:00 pm EDT
- Contributed by: Dirk
- Views: 8,617
- A cross site scripting issue, due to the use of the (unfiltered) variable
$topic
in most of the language files (thanks to the anonymous submitter of bug #293). - It was possible to post comments to stories and polls for which comments had been disabled. The comments were never displayed, though, but did show up in the What's New block.
The upgrade to 1.3.9sr2 also includes a lib-plugins.php that fixes problems with plugins on PHP 5. The complete 1.3.9sr2 tarball also includes updated PEAR packages that should resolve email problems that some users had (see this story for details).