/**
* image.php
*
- * Copyright (c) 1999-2002 The SquirrelMail Project Team
+ * Copyright (c) 1999-2003 The SquirrelMail Project Team
* Licensed under the GNU GPL. For full terms see the file COPYING.
*
* This file shows an attached image
displayPageHeader($color, 'None');
/* globals */
-
$mailbox = $_GET['mailbox'];
-$passed_id = $_GET['passed_id'];
-
+$passed_id = (int) $_GET['passed_id'];
+$ent_id = $_GET['ent_id'];
+$QUERY_STRING = $_SERVER['QUERY_STRING'];
/* end globals */
echo '<BR>' .
'<B><CENTER>' .
_("Viewing an image attachment") . " - ";
-$msg_url = 'read_body.php?' . $QUERY_STRING;
+$msg_url = 'read_body.php?' . urlencode(strip_tags(urldecode($QUERY_STRING)));
$msg_url = set_url_var($msg_url, 'ent_id', 0);
echo '<a href="'.$msg_url.'">'. _("View message") . '</a>';
$DownloadLink = '../src/download.php?passed_id=' . $passed_id .
'&mailbox=' . urlencode($mailbox) .
- '&ent_id=' . $ent_id . '&absolute_dl=true';
+ '&ent_id=' . urlencode($ent_id) . '&absolute_dl=true';
echo '</b></td></tr>' . "\n" .
'<tr><td align=center><A HREF="' . $DownloadLink . '">' .