Re: About new security in SquirrelMail 1.4.20rc2

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



El 11/09/09 19:51, Paul Lesniewski escribió:
> On Fri, Sep 11, 2009 at 1:35 AM, Fernando Gozalo<fgozalo@xxxxxxxxxxx>  wrote:
>> Hello:
>>
>> Please, consider to change in /src/options.php the line
>>
>> if (!sqgetGlobalVar('smtoken',$submitted_token, SQ_POST)) {
>>                                                  ^^^^^^^
>> for
>>
>> if (!sqgetGlobalVar('smtoken',$submitted_token, SQ_FORM)) {
>>                                                  ^^^^^^^
>>
>> Plugins that return to options.php after save only can pass the token in
>> URL.
>
> Please provide an example plugin
>

It's a custom plugin.

I thought that "newmail" have the same problem, but looking more 
carefully is posibly that "newmail/newmail_opt.php" only need a hidden 
'smtoken'.

Have the change implications I don't see?

Thanks,
Fernando.



------------------------------------------------------------------------------
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
trial. Simplify your report design, integration and deployment - and focus on 
what you do best, core application coding. Discover what's new with 
Crystal Reports now.  http://p.sf.net/sfu/bobj-july
-----
squirrelmail-users mailing list
Posting guidelines: http://squirrelmail.org/postingguidelines
List address: squirrelmail-users@xxxxxxxxxxxxxxxxxxxxx
List archives: http://news.gmane.org/gmane.mail.squirrelmail.user
List info (subscribe/unsubscribe/change options): https://lists.sourceforge.net/lists/listinfo/squirrelmail-users


[Index of Archives]     [Video For Linux]     [Yosemite News]     [Yosemite Photos]     [gtk]     [KDE]     [Cyrus SASL]     [Gimp on Windows]     [Steve's Art]     [Webcams]

  Powered by Linux