Fixed improper sanitizing of PHP_SELF and the lack of sanitizing of QUERY_STRING...
authorpdontthink <pdontthink@7612ce4b-ef26-0410-bec9-ea0150e637f0>
Mon, 11 May 2009 21:49:23 +0000 (21:49 +0000)
committerpdontthink <pdontthink@7612ce4b-ef26-0410-bec9-ea0150e637f0>
Mon, 11 May 2009 21:49:23 +0000 (21:49 +0000)
commit960b7ec2d43bd8d3b15be292b7558a18182056a7
treeeb6ec9963af5221efd3457cd1987b6368d8354ef
parent39352565ef2e2f1d438b23a5c291ec9e655ae8a0
Fixed improper sanitizing of PHP_SELF and the lack of sanitizing of QUERY_STRING server environment variables. Thanks to Niels Teusink and Christian Balzer. (CVE-2009-1578)

git-svn-id: https://svn.code.sf.net/p/squirrelmail/code/trunk/squirrelmail@13669 7612ce4b-ef26-0410-bec9-ea0150e637f0
doc/ChangeLog
include/init.php