Thread:Extension talk:Lockdown/Security Flaw/reply (2)

For myself I fixed it using: diff -udpr includes//parser/Parser.php /root/mediawiki/mediawiki-1.16.4/includes/parser/Parser.php --- includes//parser/Parser.php	2011-08-03 09:43:32.000000000 -0400 +++ /root/mediawiki/mediawiki-1.16.4/includes/parser/Parser.php	2010-05-11 22:12:12.000000000 -0400 @@ -3154,7 +3154,7 @@ class Parser $deps = array; // Loop to fetch the article, with up to 1 redirect -		for ( $i = 0; $i < 1 && is_object( $title ); $i++ ) { +		for ( $i = 0; $i < 2 && is_object( $title ); $i++ ) { # Give extensions a chance to select the revision instead $id = false; // Assume current wfRunHooks( 'BeforeParserFetchTemplateAndtitle', array( $parser, &$title, &$skip, &$id ) );

Almost the same as removing the loop, Mediawiki won't fetch redirect in inclusion now.