--- - branch: MAIN date: Thu Nov 12 22:05:55 UTC 2009 files: - new: '1.6' old: '1.5' path: pkgsrc/www/wordpress/Makefile pathrev: pkgsrc/www/wordpress/Makefile@1.6 type: modified - new: '1.4' old: '1.3' path: pkgsrc/www/wordpress/PLIST pathrev: pkgsrc/www/wordpress/PLIST@1.4 type: modified - new: '1.5' old: '1.4' path: pkgsrc/www/wordpress/distinfo pathrev: pkgsrc/www/wordpress/distinfo@1.5 type: modified id: 20091112T220555Z.6e2c3489f6fd82e247d7071f9988d697c7b51e2f log: | Update to 2.8.6 - 2.8.5 * Fix for trackback DOS * Removal of permalink_structure eval * Remove some create_function() calls * Disallow unfiltered uploads by default, even for admins. Enable it again with define('ALLOW_UNFILTERED_UPLOADS', true); in wp-config.php * Add extra escapes here and there for some backside coverage * Retire two old importers * A few small bug fixes - 2.8.6 * Fixed an XSS vulnerability in Press This * Fixed issue with sanitizing uploaded file names that can be exploited in certain Apache configurations module: pkgsrc subject: 'CVS commit: pkgsrc/www/wordpress' unixtime: '1258063555' user: adrianp