Applying revision 4459 to trunk.
Escaping some user controlled variables.
Applying revsion 4457 to trunk.
Escape usage of PHP_SELF in form action.
Applying revision 4455 to trunk.
Bug / security fix in getPivotxURL().
Using absolute paths every where in the head.
Applying rev 4452 to trunk.
Bug fix in check of allowed file extensions.
Apply revision 4450 to trunk.