30 Aug
2007
30 Aug
'07
5:53 p.m.
User: goba Branch: HEAD Date: Thu, 30 Aug 2007 15:53:40 +0000 Modified files: /includes bootstrap.inc common.inc Log message: #171606 by Heine: ported security fix from Drupal 4.7/5; use SCRIPT_NAME instead of PHP_SELF in links to avoid XSS holes Links: http://cvs.drupal.org/diff.php?path=drupal/includes/bootstrap.inc&old=1.184&... http://cvs.drupal.org/diff.php?path=drupal/includes/common.inc&old=1.681&new...