瀏覽代碼

patch a security hole in UW

lbergman 24 年之前
父節點
當前提交
4099ca6ca4
共有 1 個文件被更改,包括 5 次插入0 次删除
  1. 5 0
      src/right_main.php

+ 5 - 0
src/right_main.php

@@ -79,6 +79,11 @@
       $startMessage = 1;
    }
 
+   // compensate for the UW vulnerability
+   if ($imap_server_type == "uw" && strstr($mailbox, "../")) {
+      $mailbox = "INBOX";
+   }
+
    sqimap_mailbox_select($imapConnection, $mailbox);
    displayPageHeader($color, $mailbox);