[Tickets #4253] Re: unescaped html entities

bugs@bugs.horde.org bugs at bugs.horde.org
Sat Nov 4 00:33:25 PST 2006


DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: https://dev.horde.org/horde/whups/ticket/?id=4253
-----------------------------------------------------------------------
 Ticket             | 4253
 Updated By         | Matt Selsky <selsky at columbia.edu>
 Summary            | unescaped html entities
 Queue              | IMP
 Version            | HEAD
 Type               | Bug
 State              | Resolved
 Priority           | 1. Low
 Owners             | Matt Selsky
-----------------------------------------------------------------------


Matt Selsky <selsky at columbia.edu> (2006-11-04 00:33) wrote:

When reading a PGP encrypted message, no passphrase stored yet, and pop-up
blocking enabled in Safari, "&actionID" is not escaped properly:

<a href="#"
onclick="popup_imp('/horde/imp/pgp.php?reload=%2Fhorde%2Fimp%2Fmessage.php%3Fmailbox%3D%252A%252Asearch_5quwy0lckx44ss440480ks%26amp%3Bindex%3D6595%26amp%3Bthismailbox%3DSent%2BMessages&actionID=open_passphrase_dialog',450,200);
return false;" title="This message has been encrypted with PGP. You must
enter the passphrase for your PGP private key before it can be
decrypted.">You must enter the passphrase for your PGP private key to view
this message.</a>




More information about the bugs mailing list