Browse Source

sanitize server error messages in read_body aswell

Thijs Kinkhorst 19 years ago
parent
commit
b8d612ab58
1 changed files with 3 additions and 3 deletions
  1. 3 3
      src/read_body.php

+ 3 - 3
src/read_body.php

@@ -262,9 +262,9 @@ function SendMDN ( $mailbox, $passed_id, $sender, $message, $imapConnection) {
         $success = $deliver->finalizeStream($stream);
     }
     if (!$success) {
-        $msg  = $deliver->dlv_msg . '<br />' .
-                _("Server replied:") . ' ' . $deliver->dlv_ret_nr . ' ' .
-                $deliver->dlv_server_msg;
+        $msg  = htmlspecialchars($deliver->dlv_msg) . '<br />' .
+                _("Server replied:") . ' ' . htmlspecialchars($deliver->dlv_ret_nr . ' ' .
+                $deliver->dlv_server_msg);
         require_once(SM_PATH . 'functions/display_messages.php');
         plain_error_message($msg, $color);
     } else {