Changeset 482 in subversion


Ignore:
Timestamp:
Feb 16, 2007 9:38:12 AM (6 years ago)
Author:
robin
Message:

Fix XSS vulnerability (closes #1484254).

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/roundcubemail/program/steps/mail/func.inc

    r451 r482  
    3131 
    3232// set imap properties and session vars 
    33 if (strlen($_GET['_mbox'])) 
    34   { 
    35   $IMAP->set_mailbox($_GET['_mbox']); 
    36   $_SESSION['mbox'] = $_GET['_mbox']; 
     33if (strlen($mbox = get_input_value('_mbox', RCUBE_INPUT_GET))) 
     34  { 
     35  $IMAP->set_mailbox($mbox); 
     36  $_SESSION['mbox'] = $mbox; 
    3737  } 
    3838 
Note: See TracChangeset for help on using the changeset viewer.