#89 wrong compensate for UW vulnerability

closed
nobody
Folders (53)
5
2001-05-08
2001-03-15
No

in right_main.php on line 84:

// compensate for the UW vulnerability
if ($imap_server_type == 'uw' && strstr
($mailbox, '/')) {
$mailbox = 'INBOX';
}

is incorrect. UW imap supports subfolders, but he
didn't mixed folders with messages. to test after '/'
is not correct cause imap uses folders sperated by '/'
or '\' (system depended).

remove this three lines from code.

poelzi

Discussion

  • Fred Wiseman

    Fred Wiseman - 2001-03-19

    Logged In: YES
    user_id=19855

    use this to solve the problem.

    if ($imap_server_type == 'uw' && ereg("^/|\.\./",
    $mailbox)) {
    $mailbox = 'INBOX';
    }

     
  • Tyler Akins

    Tyler Akins - 2001-05-08
    • status: open --> closed
     
  • Tyler Akins

    Tyler Akins - 2001-05-08

    Logged In: YES
    user_id=73968

    Solution was stated
    Code was updated a while ago

     

Log in to post a comment.