Transposh - Breaking language barriers

The transposh.org wordpress plugin showcase and support site

  • Home
  • Contact us
  • Download
  • FAQ
    • Donate
  • Tutorial
    • Widget Showcase
  • About

Version 0.6.6 – Finally! a security release

November 12, 2010 by Ofer 13 Comments

By Dmitry Baranovskiy - http://www.flickr.com/photos/dmitry-baranovskiy/
Cross Site Scripting -> XSS

We would like to thank Joshua Hansen and Scott Caveza for their help in identifying and helping us debug two XSS vulnerabilities that had the potential to effect users using internet explorer browser with versions lower than 8, or when xss protection was explicitly off. We avoided the urge to call this version 0.6.6.6 and resumed the regular naming policies. Those vulnerabilities don’t pose any risk to webmasters or hosters using Transposh, but to users that might trust scripts from these sites by using the sneaky XSS method.

This release also bundles two other changes that were already committed and would have probably waited for a later release otherwise, the first being a small improvement to the parser, enabling support for some more html “breaker entities” such as ’ which were created by software trying to outsmart the user, we would like to thank archon810 on his help in this bug report.

Last but not least is a change in the support for Google Sitemaps XML generator, the patch has one letter removed in order to have proper support for php5.3, and on other good news, the coming version 4 of this plugin has support already built in, this version also helps in breaking the 50k url limits that some users had. So we would to thank Arne Brachhold on his great work on this project.

So everybody, go and upgrade! just because finding an image to match this post was such a difficult fit.

Filed Under: Release announcements Tagged With: google-xml-sitemaps, minor, release, securityfix, wordpress plugin

Comments

  1. Anphicle says

    November 12, 2010 at 2:05 am

    Great, keep up the good work!

    Reply
  2. Peter says

    November 12, 2010 at 10:04 am

    Good day

    What does the message:
    “Google Sitemaps XML Generator, the patch ”
    I : Sitemap Version 3.2.4 and Transposh version 0.6.6

    But there are no language in the xml generated pages.

    Regards
    Peter

    Reply
    • ofer says

      November 12, 2010 at 10:33 am

      Hello,

      Make sure you have the latest patch, eg. remove the & from the previous patch, I have updated the changelog, and now the FAQ with this new patch, if you still have problems I’ll send you the patched file.

      Good luck

      Reply
  3. Timo Ligi says

    November 12, 2010 at 8:59 pm

    Tere päevast

    Kui ma panen tööle “Google Sitemaps XML Generator” ja Transposh version 0.6.6 siis saan Google sitemaps XML-is vastuseks “XML Parsing Error: no element found, Line Number 1, Column 1:” Samas kui võtan maha Transposh version 0.6.6, siis Google sitemaps töötab.

    Timo

    Reply
    • ofer says

      November 12, 2010 at 11:53 pm

      An updated patch can be found here: http://trac.transposh.org/wiki/PluginSupportMatrix

      Reply
  4. Elmar says

    November 12, 2010 at 10:24 pm

    Same problem as in earlier versions since 0.6.3: After upgrade I see “Okt_Oktober_abbreviation” instead of “OKT” in my blog. Same with any short form of month when German name is different from English name. So 0.66 deleted again and version 0.61 again – it works. And proofes the plugin makes something wrong. And I don’t want to use a plugin that I have to work with by myself editing PHP… So any upgrade in the future will not fix it?

    Reply
    • ofer says

      November 12, 2010 at 10:38 pm

      First, please create a ticket in the trac (trac.transposh.org)
      Second, please try to provide more details regarding your system (which WP you use, etc)
      Third, you can disable the gettext integration, should probably solve your issue better than downgrading to 0.6.1

      And good luck…

      Reply
      • Elmar says

        November 13, 2010 at 12:04 am

        I did create a ticket…

        Reply
        • Elmar says

          November 13, 2010 at 12:37 am

          Quick and successful help – I don’t need to edit PHP, only to change one option in the options. Great! Now it works perfect again! Thank you so much!

          Reply
  5. nvr says

    November 13, 2010 at 12:26 am

    it is possible to permanent disable e-mail adresses from translation? (both strings and urls)

    I mean the built-in function, not every time the use of no_translate class.

    Reply
    • ofer says

      November 13, 2010 at 12:55 am

      As far as I know, at least urls (ones that are properly marked as ones) will not be translated, checking for every word in every phrase if it might be a url or email might create some substantial overhead.

      Reply
  6. Ivo Minchev says

    December 17, 2010 at 8:05 pm

    I have a Backup problem. I get the following “500 – Couldn’t resolve host ‘svc.transposh.org'” when I click the “Do Backup Now” button.

    Reply
    • ofer says

      December 17, 2010 at 11:48 pm

      Thanks for reporting,

      I guess that would be yet another problem with cloudflare dns, I will fix this in the coming day.

      Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Translation

🇺🇸🇸🇦🇧🇩🏴󠁥󠁳󠁣󠁴󠁿🇨🇳🇹🇼🇭🇷🇨🇿🇩🇰🇳🇱🇪🇪🇵🇭🇫🇮🇫🇷🇩🇪🇬🇷🇮🇳🇮🇱🇮🇳🇭🇺🇮🇩🇮🇹🇯🇵🇮🇳🇰🇷🇱🇻🇱🇹🇲🇾🇮🇳🇮🇳🇳🇴🇵🇱🇵🇹🇵🇰🇷🇴🇷🇺🇷🇸🇸🇰🇸🇮🇪🇸🇸🇪🇮🇳🇮🇳🇹🇭🇹🇷🇺🇦🇵🇰🇻🇳
 Edit Translation

Sponsors

We would like to thank our sponsors!

Collectors of stamps, coins, banknotes, TCGs, video games and more enjoy Transposh-translated Colnect in 62 languages. Swap, exchange, mange your personal collection using our catalog. What do you collect?
Connecting collectors: coins, stamps and more!

Recent Comments

  1. fhzy on Version 1.0.9.5 – Fighting the code rotApril 24, 2025
  2. Stacy on Version 1.0.9.5 – Fighting the code rotApril 8, 2025
  3. wu on Version 1.0.9.5 – Fighting the code rotApril 5, 2025
  4. Lulu Cheng on Version 1.0.9.5 – Fighting the code rotMarch 30, 2025
  5. Ofer on Version 1.0.9.5 – Fighting the code rotMarch 30, 2025

Tags

0.7 0.9 ajax bing (msn) translator birthday buddypress bugfix control center css sprites debug donated translation donations emoji fake interviews flags flag sprites full version gettext google-xml-sitemaps google translate major minor more languages parser professional translation release rss securityfix SEO shortcode shortcodes speed enhancements start themeroller trac ui video widget wordpress.org wordpress 2.8 wordpress 3.0 wordpress MU wordpress plugin wp-super-cache xcache

Development feed

  • Releasing 1.0.9.6
    April 5, 2025
  • Minor code improvements to edit interface and remove some deprecation…
    March 22, 2025
  • Fix undefined array key
    March 18, 2025
  • Finally support jQueryUI 1.14.1, shorten code nicely
    March 17, 2025
  • Releasing 1.0.9.5
    March 15, 2025

Social

  • Facebook
  • Twitter

Design by LPK Studio

Entries (RSS) and Comments (RSS)

Copyright © 2025 · Transposh LPK Studio on Genesis Framework · WordPress · Log in