|
![]() [ View full size screenshot ] |
| Version | Date Released | Status | Release Notes |
| 2.4.4 RC 1 | May 30, 2012 | New Release | · Fixed regression from 2.4.3rc3 causing same-site stylesheets to be checked for mime type mismatches and XSLT inclusions to be incorrectly blocked |
| 2.4.3 | May 28, 2012 | New Release | · Fixed JS links detection not resolving JS string escapes · Fixed HTML 5 parser detection in META refresh processing being broken by a removed browser preference · Fixed exception raised by inclusion type checks when parent document's URI has no host · [XSS] Better detection of free inline script injections (without string literal evasion) inside function calls · The noscript.allowedMimeRegExp preference now applies also to Java, Flash and Silverlight mime types |
| 2.4.3 RC 2 | May 25, 2012 | New Release | · [XSS] Better detection of free inline script injections (without string literal evasion) inside function calls |
| 2.4.2 | May 21, 2012 | New Release | · [ABE] IPv6 link-local addresses (fe80:/10) are not considered belonging · to the LAN anymore for the purpose of cross-zone request forgery checks · in order to safely work-around DNS misconfiguration issues in the wild · [ABE] Fixed router WEB UI fingerprinting failing on some devices · because of redirection loops · [XSS] Protection against HPP attacks exploiting URL parsing quirks · specific to ASP Classic · Fixed first application updates check failing on Nightly · [XSS] Fixed false positive regression on some file hosting sites |
| 2.4.2 RC4 | May 20, 2012 | New Release | · [XSS] Fixed regression blocking any suspect HPP attack silently |
| 2.4.2 RC2 | May 12, 2012 | New Release | · Fixed first application updates check failing on Nightly (bug 754393) |
| 2.4.1 | May 12, 2012 | New Release | · [XSS] Protection against exploitation of classic MS ASP's coalescing of same-name query parameters · [XSS] Protection against URL injections in in window.name · [XSS] Fixed case-sensitivity bug in detection of unicode escape sequences · [Surrogate] adagionet.com inclusion surrogate · Fixed "Allow sites open through bookmarks" regression · [XSS] Fixed bug in the InjectionChecker tokenization · Added inclusion type check exception to the lesscss Google Code file repository, often used as a CDN |
| 2.4.1 RC 3 | May 11, 2012 | New Release | · [XSS] Fixed bug in the InjectionChecker tokenization · Added inclusion type check exception to the lesscss Google Code file repository, often used as a CDN |
| 2.4 | May 6, 2012 | New Release | · [XSS] Improved global exception injection detection · [XSS] Fixed bug in late window.name payload checking · [Locale] Fixed broken overlay on Basque localized browsers |
| 2.4 RC 6 | Apr 30, 2012 | New Release | · [Surrogate] Skimlinks surrogate script. |