The following issue has been SUBMITTED. ====================================================================== http://www.dbmail.org/mantis/view.php?id=693 ====================================================================== Reported By: gordan Assigned To: ====================================================================== Project: DBMail Issue ID: 693 Category: Database layer Reproducibility: always Severity: minor Priority: normal Status: new target: ====================================================================== Date Submitted: 02-May-08 11:46 CEST Last Modified: 02-May-08 11:46 CEST ====================================================================== Summary: Single quotes in folder names render the folder inaccessible and undeletable Description: A folder with single quotes in the name can be created, but cannot be accessed/used/deleted via the IMAP interface.
This seems like a SQL quoting issue, which may indicate some potential SQL injectionattack vectors being available. ====================================================================== Issue History Date Modified Username Field Change ====================================================================== 02-May-08 11:46 gordan New Issue ====================================================================== _______________________________________________ Dbmail-dev mailing list [email protected] http://twister.fastxs.net/mailman/listinfo/dbmail-dev
