Changes for version 1.5

  • Fixed vulnerability in the translation of page param into file name. Allowed someone to maliciously put '../../', etc into the file name and retrieve arbitrary documents from the file system if remote_fetch was not enabled.

Modules

module to allow users to send HTML pages to friends.