package squirrelmail
# Fixed in r95 by jeroen
tag 292714 + pending
thanks

These bugs are fixed in revision 95 by jeroen
and will likely get fixed in the next upload.
Log message:
Thijs Kinkhorst:
* Close security hole where URL-manipulation in combination with
  register_globals and allow_url_fopen both set to On could lead to
  remote code execution as the www-data user. (Closes: #292714).
* [CAN-2005-0104] Fix possible XSS issues in src/webmail.php.





-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to