security possible PHP code injection on custom resources at display() or fetch() calls if the resource does not sanitize the template name bugfix fix 'mkdir(): File ...