Browse Source

patch a security hole in UW

lbergman 24 years ago
parent
commit
4099ca6ca4
1 changed files with 5 additions and 0 deletions
  1. 5 0
      src/right_main.php

+ 5 - 0
src/right_main.php

@@ -79,6 +79,11 @@
       $startMessage = 1;
       $startMessage = 1;
    }
    }
 
 
+   // compensate for the UW vulnerability
+   if ($imap_server_type == "uw" && strstr($mailbox, "../")) {
+      $mailbox = "INBOX";
+   }
+
    sqimap_mailbox_select($imapConnection, $mailbox);
    sqimap_mailbox_select($imapConnection, $mailbox);
    displayPageHeader($color, $mailbox);
    displayPageHeader($color, $mailbox);