}
if ($totalNew > 0 && $newmail_enable == 'on' && $newmail_media != '' ) {
- echo "<EMBED SRC=\"$newmail_media\" HIDDEN=TRUE AUTOSTART=TRUE>\n";
+ echo '<EMBED SRC="'.htmlspecialchars($newmail_media) .
+ "\" HIDDEN=\"TRUE\" AUTOSTART=\"TRUE\">\n";
}
if ($totalNew > 0 && $newmail_popup == 'on') {
echo "<SCRIPT LANGUAGE=\"JavaScript\">\n".