Commit d6c7b4cf authored by Gábor Hojtsy's avatar Gábor Hojtsy

Drupal 6.1; including #227608 (SA-2008-18)

parent c709e591
// $Id$
Drupal 6.1-dev, xxxx-xx-xx (development version)
-----------------------
Drupal 6.1, 2008-02-27
----------------------
- fixed a variety of small bugs.
- fixed a security issue (Cross site scripting), see SA-2008-018
Drupal 6.0, 2008-02-13
----------------------
......
......@@ -577,7 +577,7 @@ function drupal_error_handler($errno, $message, $filename, $line, $context) {
return;
}
if ($errno & (E_ALL)) {
if ($errno & (E_ALL ^ E_NOTICE)) {
$types = array(1 => 'error', 2 => 'warning', 4 => 'parse error', 8 => 'notice', 16 => 'core error', 32 => 'core warning', 64 => 'compile error', 128 => 'compile warning', 256 => 'user error', 512 => 'user warning', 1024 => 'user notice', 2048 => 'strict warning', 4096 => 'recoverable fatal error');
// For database errors, we want the line number/file name of the place that
......
......@@ -51,7 +51,8 @@ Drupal.checkPlain = function(str) {
str = String(str);
var replace = { '&': '&amp;', '"': '&quot;', '<': '&lt;', '>': '&gt;' };
for (var character in replace) {
str = str.replace(character, replace[character]);
var regex = new RegExp(character, 'g');
str = str.replace(regex, replace[character]);
}
return str;
};
......
......@@ -11,7 +11,7 @@
* Menu callback; presents the node editing form, or redirects to delete confirmation.
*/
function node_page_edit($node) {
drupal_set_title($node->title);
drupal_set_title(check_plain($node->title));
return drupal_get_form($node->type .'_node_form', $node);
}
......
......@@ -9,7 +9,7 @@
/**
* The current system version.
*/
define('VERSION', '6.1-dev');
define('VERSION', '6.1');
/**
* Core API compatibility.
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment