06.02.09

Rating:        Based on 5 ratings
Reviewed:  5 reviews
Downloads: 8273
Released: Aug 15, 2013
Updated: Aug 15, 2013 by jbrinkman
Dev status: Stable Help Icon

Recommended Download

Application 6.2.9 - New Install
application, 45732K, uploaded Aug 13, 2013 - 3144 downloads

Other Available Downloads

Application 6.2.9 - Version Upgrade
application, 34778K, uploaded Aug 13, 2013 - 3556 downloads
Source Code 6.2.9 - Source Code (New Install + Source Code)
source code, 118628K, uploaded Aug 13, 2013 - 898 downloads
Application 6.2.9 - Symbol Files
application, 1884K, uploaded Aug 13, 2013 - 183 downloads
Application 6.2.9 - Web Platform Installer
application, 45788K, uploaded Aug 13, 2013 - 298 downloads
Application 6.2.9 - Web Platform Installer - Pro
application, 69874K, uploaded Aug 13, 2013 - 194 downloads

Release Notes

Major Highlights

  • none

Security Fixes

  • Fixed potential reflective xss issue
  • Fixed issue where malformed html may allow XSS
  • Fixed issue that could lead to redirect 'Phishing' attack

Updated Modules/Providers

Modules

  • none

Providers

  • None

Reviews for this release

     
Please note, the 6.x branch is for security fixes only, other bugs/enhancements go into the 7.x branches. There is little point complaining about non-security bugs not being fixed in 6.x as this is a legacy branch(incidentally the _blank bug has been fixed in 7.x) jcbarreau , I've logged that & will get it fixed for 6.3.0 (as it was a bug introduced in 6.2.9 whilst trying to fix a security issue)
by cathalconnolly on Oct 1, 2013 at 3:03 PM
     
Still has not resolve issue 24119 that was introduced in 6.2.5. "_new" is an incorrect tag to use on links and should use "_blank". This still causes documents opened as links to be opened up incorrectly and through a JavaScript bug.
by sirish on Sep 5, 2013 at 3:26 PM
     
New version DNN has fewer stars. so sad :(
by thienvc on Sep 4, 2013 at 6:58 AM
     
Hint. If you put the word "Stable" after every release you ever make... the word becomes meaningless! Try using some programming protocol with your releases.
by InteractiveWebs on Aug 26, 2013 at 7:22 AM
     
Tried for the first time, got an error: Compiler Error Message: CS0117: 'DotNetNuke.UI.Utilities.DNNClientAPI' does not contain a definition for 'SetScrollTop. Line 750: if (!String.IsNullOrEmpty(ScrollTop.Value)) Line 751: { Line 752: DNNClientAPI.SetScrollTop(Page); Line 753: ScrollTop.Value = ScrollTop.Value; Line 754: }
by jcbarreau on Aug 15, 2013 at 7:55 PM