Re: Bug in squirrelmail-20111024_0200-SVN, addrbook_search_html.php
Paul Lesniewski <[email protected]> Mon, 14 Nov 2011 18:06:14 -0800
| Newsgroups | gmane.mail.squirrelmail.devel |
|---|---|
| Message-ID | <CAHog114D44DJzjOFDd9RaqVEEd3G5hBc0E=nmQNhgPSu86ThjQ@mail.gmail.com> |
On Mon, Nov 14, 2011 at 5:49 PM, Paul Lesniewski <[email protected]> wrote: > Hi Dave, sorry for the delay. > > On Mon, Oct 24, 2011 at 10:52 AM, Dave McMurtrie <[email protected]> wrote: >> Squirrelmail version: 1.5.2 (20111024_0200-SVN) >> >> Every plugin installed: >> >> $plugins[] = 'cmumenuline'; (written here) >> $plugins[] = 'compose_extras'; >> $plugins[] = 'useracl'; >> $plugins[] = 'check_quota'; >> $plugins[] = 'add_address'; >> $plugins[] = 'cmuldapdefault'; (written here) >> $plugins[] = 'ldapquery'; >> $plugins[] = 'message_details'; >> >> PHP version: 5.2.6 >> >> Web server: Apache 1.3.39 >> >> IMAP server: Cyrus 2.4.x >> >> SMTP server: sendmail 8.14.4 >> >> OS: Linux, based on fc3 >> >> Details about the bug: >> >> From the message view, if you click the "Forward" button, then click >> the "Addresses" button to add an address, the body of the message will >> corrupt the addressbook view due to the "body" hidden field not being >> escaped. >> >> The following patch resolves this issue: > > This was fixed in September - looks like you're using a version from > October. Ha! I forgot September comes before October. :-) Do you use a custom template set? Can you please check your copy of templates/default/input.tpl? > The "better" fix is in templates/default/input.tpl, although > even that fix isn't ideal in the long term. Here's the commit you'd > need if you don't want to install a new snapshot. > > http://squirrelmail.svn.sourceforge.net/viewvc/squirrelmail?view=revision&revision=14145 > >> --- src/addrbook_search_html.php.orig 2011-10-24 13:27:42.000000000 -0400 >> +++ src/addrbook_search_html.php 2011-10-24 13:35:13.000000000 -0400 >> @@ -47,9 +47,9 @@ >> >> //FIXME Do not echo HTML from the core. This file already uses >> templates mostly, so why are we echoing here at all?!? >> if (substr($body, 0, 1) == "\r") { >> - echo addHidden('body', "\n".$body); >> + echo addHidden('body', "\n".htmlspecialchars($body)); >> } else { >> - echo addHidden('body', $body); >> + echo addHidden('body', htmlspecialchars($body)); >> } >> >> if (is_object($composeMessage) && $composeMessage->entities) > > -- > Paul Lesniewski > SquirrelMail Team > Please support Open Source Software by donating to SquirrelMail! > http://squirrelmail.org/donate_paul_lesniewski.php > -- Paul Lesniewski SquirrelMail Team Please support Open Source Software by donating to SquirrelMail! http://squirrelmail.org/donate_paul_lesniewski.php ------------------------------------------------------------------------------ RSA(R) Conference 2012 Save $700 by Nov 18 Register now http://p.sf.net/sfu/rsa-sfdev2dev1 ----- squirrelmail-devel mailing list Posting guidelines: http://squirrelmail.org/postingguidelines List address: [email protected] List archives: http://news.gmane.org/gmane.mail.squirrelmail.devel List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-devel