On Wed, Jul 23, 2008 at 2:20 PM, Jeremy Mann <[EMAIL PROTECTED]> wrote:
>> On Wed, Jul 23, 2008 at 2:02 PM, Jeremy Mann <[EMAIL PROTECTED]>
>>
>> What did you/they check?  Did you try uploading a file using a normal
>> file upload widget on a test page?
>
> Can you give me an example on an upload widget? You may be on to something.

First three google results:

http://www.cs.tut.fi/~jkorpela/forms/file.html
http://cgi-lib.berkeley.edu/ex/fup.html
http://cgi-lib.berkeley.edu/ex/fup.html

>> SM does nothing special with file uploads.  It waits for the web
>> server to do the upload and simply moves it to the SM attachments
>> directory.  There is little chance it is a SM problem IMO.
>>
>>> SquirrelMail 1.4.6 (and tested with 1.5.1)
>>
>> Never use 1.5.1.  If using 1.4, you REALLY SHOULD upgrade.
>
> I had it on the server for awhile and wanted to check to see if it was our
> current 1.4.6 install causing the problem.

If you have 1.4.6 running anywhere, it is vulnerable to any number of
known exploits.  You are shooting yourself in the foot by using it.

-------------------------------------------------------------------------
This SF.Net email is sponsored by the Moblin Your Move Developer's challenge
Build the coolest Linux based applications with Moblin SDK & win great prizes
Grand prize is a trip for two to an Open Source event anywhere in the world
http://moblin-contest.org/redirect.php?banner_id=100&url=/
-----
squirrelmail-users mailing list
Posting guidelines: http://squirrelmail.org/postingguidelines
List address: [email protected]
List archives: http://news.gmane.org/gmane.mail.squirrelmail.user
List info (subscribe/unsubscribe/change options): 
https://lists.sourceforge.net/lists/listinfo/squirrelmail-users

Reply via email to