Do you mean 1.1.6?? http://weblog.rubyonrails.org/2006/8/10/rails-1-1-6-backports-and-full-disclosure
On 8/10/06, Kent Sibilev <[EMAIL PROTECTED]> wrote:
Hi,I think there is still a major vulnerability exists in the latest Rails 1.1.5.The problem is in the routing.rb file and safe_load_paths method
I've been sitting on an ActiveResource patch for a few weeks, waiting
to get some feedback from David. But, I see other folks like Jeremy
are starting to use it, so I committed my patch:
http://dev.rubyonrails.org/changeset/4890
It gets all the basic operations in working order, and adds suppor
"bitsweat" has kicked AR/Oracle while it was down...
http://dev.rubyonrails.org/changeset/4893
r4893 | bitsweat | 2006-08-31 22:31:56 -0700 (Thu, 31 Aug 2006) | 1 line
has_many :through conditions are sanitized by the associ
Evening,
Alright folks, as Jeremy Kemper mentioned I'm working on a set of
"triage" scripts for the Rails trac using RFuzz to go through all the
tickets and clean them out. I've talked this over with the core guys,
and they're behind it.
I'm calling this set of scripts "THE MAGGOT" thanks to has